Impact
The vulnerability resides in the change_password function of the nas.cgi script on the Wavlink WL‑NU516U1 router running firmware 708c073‑mt7628. By manipulating the User1Passwd argument, an attacker can overflow a stack buffer, potentially gaining arbitrary code execution or causing denial of service. This is a classic stack overflow weakness associated with CWE‑119 and CWE‑121.
Affected Systems
The flaw affects only the Wavlink WL‑NU516U1 model with firmware build 708c073‑mt7628. No other versions are listed as impacted. The vulnerable code lies within the device’s management interface exposed remotely via nas.cgi.
Risk and Exploitability
The CVSS score of 9.3 reflects critical severity. EPSS data is not available, yet the exploit is publicly documented and can be executed remotely through the web interface. The vulnerability is not currently listed in the CISA KEV catalog, but the combination of high CVSS, remote exploitability, and existence of a public exploit demands urgent remediation. The attack vector is inferred to be the device’s web management portal, where a crafted payload targeting the User1Passwd field can trigger the overflow.
OpenCVE Enrichment