CVE-2026-18589 | Wavlink WL-NU516U1 708c073-mt7628 nas.cgi change_password User1Passwd stack-based overflow
A vulnerability labeled as critical has been found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow.
This vulnerability is identified as CVE-2026-18589. The attack can be executed remotely. Additionally, an exploit exists.
The affected component should be upgraded.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.VulDB Recent EntriesRead More