A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to out-of-bounds write. The attack may be performed from remote. The exploit has been published and may be used. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wavlink
Wavlink wl-nu516u1 |
|
| Vendors & Products |
Wavlink
Wavlink wl-nu516u1 |
Sun, 08 Mar 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to out-of-bounds write. The attack may be performed from remote. The exploit has been published and may be used. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | |
| Title | Wavlink NU516U1 login.cgi sub_401A10 out-of-bounds write | |
| Weaknesses | CWE-119 CWE-787 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-03-08T04:32:09.200Z
Updated: 2026-03-08T04:32:09.200Z
Reserved: 2026-03-07T08:56:07.678Z
Link: CVE-2026-3703
No data.
Status : Awaiting Analysis
Published: 2026-03-08T05:16:29.080
Modified: 2026-03-09T13:35:07.393
Link: CVE-2026-3703
No data.