Executive brief
A security vulnerability has been identified in the Wavlink WL-NU516U1-A, a device used for network printing and wireless connectivity. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to unauthorized access to the network or a complete disruption of the device's services.
Technical details
A stack-based buffer overflow exists in the Wavlink WL-NU516U1-A firmware version M16U1_V240425 within the /cgi-bin/wireless.cgi component. The vulnerability is located in function sub_407504, where an unsafe sprintf call processes the Guest_ssid POST parameter into a fixed-size 1028-byte stack buffer (v8) without length validation. An attacker with network access to the web management interface can provide a Guest_ssid value exceeding approximately 1000 bytes to overwrite the stack return address. On the affected MIPS architecture, this can lead to control of the $ra register and potential Remote Code Execution (RCE). A fixed firmware version has been released by the vendor.
Affected products
- Wavlink WL-NU516U1-A M16U1_V240425
Timeline
- 2026-06-29: advisory: NVD publication date
- 2026-06-22: patched: Vendor released fixed firmware version
References
- https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-06-22-5ccde97-mt7628-squashfs-sysupgrade.bin
- https://github.com/Svigo-o/Wavlink_vul/tree/main/wavlink-wl-nu516u1-wireless-guestwifi-guestssid-buffer-overflow
- https://vuldb.com/cve/CVE-2026-13539
- https://vuldb.com/submit/834024
- https://vuldb.com/vuln/374547
- https://vuldb.com/vuln/374547/cti