CVE detail
CVE-2026-18588
A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote exploitation of the attack is possible. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 6
- within the 30d window
- Peak daily
- 6
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://vuldb.com/vuln/385416/ctivuldb.com
No excerpt available.
Exploitvuldb.comAug 3, 2026, 7:16 AM - https://vuldb.com/vuln/385416vuldb.com
No excerpt available.
Exploitvuldb.comAug 3, 2026, 7:16 AM - https://vuldb.com/submit/850500vuldb.com
No excerpt available.
Exploitvuldb.comAug 3, 2026, 7:16 AM - https://vuldb.com/cve/CVE-2026-18588vuldb.com
No excerpt available.
Exploitvuldb.comAug 3, 2026, 7:16 AM No excerpt available.
Exploitgithub.comAug 3, 2026, 7:16 AM- https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-07-13-4b8a21f-mt7628-squashfs-sysupgrade.bindl.wavlink.com
No excerpt available.
referencedl.wavlink.comAug 3, 2026, 7:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-14042CVSS 2.1 · Low
A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr_cb of the file src/hss/hss-s6a-path.c of the component Dia…
- CVE-2026-19341CVSS 7.4 · High
A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of t…
- CVE-2026-18898CVSS 7.4 · High
A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument t…
- CVE-2026-18897CVSS 7.4 · High
A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulat…
- CVE-2026-18895CVSS 7.4 · High
A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argume…
- CVE-2026-18607CVSS 7.4 · High
A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 202606…