What is CVE-2026-18589?
A stack-based buffer overflow vulnerability was found in the change_password function of the nas.cgi file in Wavlink WL-NU516U1 708c073-mt7628, triggered by manipulating the User1Passwd argument. This allows remote code execution. Users should restrict access to the device's management interface and await a patch from the vendor.
Azərbaycanca: Wavlink WL-NU516U1 708c073-mt7628 cihazının nas.cgi faylındakı change_password funksiyasında User1Passwd parametrinin manipulyasiyası ilə stack-based buffer overflow zəifliyi aşkarlanıb. Bu, uzaqdan kod icrasına imkan verir. İstehsalçının yamaq buraxmasını gözləmək və cihazın idarəetmə interfeysinə girişi məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Wavlink
FAQ2
What type of vulnerability is CVE-2026-18589 in the Wavlink WL-NU516U1 and what can an attacker achieve by exploiting it?
It is a stack-based buffer overflow vulnerability in the `change_password` function of the `nas.cgi` file, triggered by manipulating the `User1Passwd` argument. An attacker can leverage this to achieve remote code execution (RCE).
What is recommended for users to mitigate CVE-2026-18589 until the vendor releases a patch?
Users are recommended to restrict access to the device's management interface while awaiting a patch from the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.