Impact
The flaw occurs in the strcpy function within the /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi component. A malicious actor can craft a specially sized HTTP_COOKIE header that overflows the stack, allowing arbitrary code execution on the device. This leads to a complete loss of confidentiality, integrity, and availability of the affected device.
Affected Systems
The vulnerability affects Wavlink WN531P3 and WN535M1 routers running firmware V250922. No other versions are listed as impacted.
Risk and Exploitability
The CVSS score of 10 denotes the highest severity. EPSS data is not available, and the issue is not listed in CISA KEV, yet public exploits have been disclosed and the flaw can be launched remotely from any network that can reach the device. The absence of a mitigation advisory does not reduce the likelihood; attackers can feed the overflow payload via the HTTP_COOKIE header to trigger arbitrary code execution.
OpenCVE Enrichment