What is CVE-2026-18588?
A stack-based buffer overflow vulnerability was found in the fgets function of the nas.cgi file on Wavlink WL-NU516U1 devices via manipulation of the CONTENT_LENGTH argument. This allows remote exploitation, and upgrading the component is recommended.
Azərbaycanca: Wavlink WL-NU516U1 cihazının nas.cgi faylındakı fgets funksiyasında CONTENT_LENGTH arqumentinin manipulyasiyası nəticəsində stack-based buffer overflow zəifliyi aşkarlanıb. Bu, uzaqdan kod icrasına imkan verə bilər, ona görə də cihazı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Wavlink
FAQ2
In which file was the CVE-2026-18588 vulnerability discovered on the Wavlink WL-NU516U1 device?
The vulnerability was discovered in the nas.cgi file on the Wavlink WL-NU516U1 device.
How can CVE-2026-18588 be exploited?
This vulnerability can be exploited by manipulating the CONTENT_LENGTH argument in the fgets function in the nas.cgi file, leading to a stack-based buffer overflow that allows remote code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.