← Zuruck zu CVEs
CVE-2026-3613
HIGH7.2
Beschreibung
A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
CVE Details
CVSS v3.1 Bewertung7.2
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienHIGH
BenutzerinteraktionNONE
Veroffentlicht3/6/2026
Zuletzt geandert3/10/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
wavlink:wl-nu516u1wavlink:wl-nu516u1_firmware
Schwachen (CWE)
CWE-119CWE-121
Referenzen
https://github.com/Wlz1112/WAVLINK-NU516-V240425/blob/main/ipaddr_Stack%20Buffer%20Overflow.md(cna@vuldb.com)
https://vuldb.com/?ctiid.349221(cna@vuldb.com)
https://vuldb.com/?id.349221(cna@vuldb.com)
https://vuldb.com/?submit.755341(cna@vuldb.com)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.