Impact
An attacker can manipulate the CONTENT_LENGTH argument to nas.cgi, causing the fgets function to overflow the stack. The stack-based buffer overflow can be exploited remotely, potentially leading to arbitrary code execution or denial of service on the device.
Affected Systems
The vulnerability exists in Wavlink WL‑NU516U1 firmware 708c073-mt7628.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack vector is remote and the flaw is a classic stack-based overflow, exploitation is feasible from an external network if the web management interface is reachable.
OpenCVE Enrichment