top of page
perceptive_background_267k.jpg

A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and…

Published:

3 augustus 2026 om 00:00:00

Alert date:

3 augustus 2026 om 20:04:46

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Mobile & IoT, Zero-Day Vulnerabilities

A stack-based buffer overflow vulnerability (CVE-2026-18607) has been identified in multiple Wavlink router models including WN572, WN570H, WN573, WN529, WN530, WN531, WN535, WN536, WN551, WN557, and NU516 up to firmware version 20260609. The vulnerability exists in the strcpy function within the upload.cgi file of the lighttpd component. Attackers can exploit this by manipulating the HTTP_COOKIE argument to trigger a stack-based buffer overflow remotely. The attack can be initiated without physical access to the device. A public exploit has been disclosed and is available for use. This affects a wide range of Wavlink networking devices, increasing the risk of widespread exploitation. The vulnerability poses a significant risk to network infrastructure security.

Technical details

Mitigation steps:

Affected products:

Wavlink WN572
Wavlink WN570H
Wavlink WN573
Wavlink WN529
Wavlink WN530
Wavlink WN531
Wavlink WN535
Wavlink WN536
Wavlink WN551
Wavlink WN557
Wavlink NU516

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page