Impact
The flaw is a stack‑based buffer overflow in the lighttpd component’s upload.cgi that copies the HTTP_COOKIE header into a fixed buffer using strcpy. Because the input is not bounded, an attacker can cause the buffer to be overwritten, potentially leading to arbitrary code execution on the affected device. The weakness is classed as CWE‑119 (buffer overflow) and CWE‑121 (stack‑based buffer overflow).
Affected Systems
Affected versions of Wavlink devices include the NU516, WN529, WN530, WN531, WN535, WN536, WN551, WN557, WN570H, WN572, WN573 and related models, specifically firmware released up to June 9, 2026.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and while the EPSS score is not listed, the vulnerability is publicly disclosed and can be triggered remotely via an HTTP request manipulating the cookie header. The exploit is not currently in the CISA KEV catalog, but the lack of a defensive patch increases the risk of exploitation by attackers expecting a high‑impact attack vector that requires no special privileges.
OpenCVE Enrichment