CVE-2026-13539General

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. Such manipulation of the argument Guest_ssid leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Exploit: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-06-29)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-06-28: 1Mentions · 2026-06-29: 4PoC Mentioned / Linked · 2026-06-29: 1Patch / Workaround · 2026-06-29: 1Technical Details · 2026-06-29: 406-2806-29
Signal classification3 categories
General
360.0%
Disclosure
120.0%
Exploit
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-281
General1
2026-06-294
Disclosure1Exploit1General2
Full discourse5 posts
  • CVE@CVEnew
    General

    CVE-2026-13539 A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the compone… https://www.cve.org/CVERecord?id=CVE-2026-13539

    Post summary

    The excerpt references CVE‑2026‑13539 and identifies the affected function, but offers no evidence of exploitation, mitigations, or a PoC.

    00020737
    58.0K followersView on X
  • DFIR Lab@DFIR_Lab
    Exploit

    🚨 HIGH: CVE-2026-13539 (CVSS 8.8) - Stack-based buffer overflow in Wavlink WL-NU516U1-A router. Remotely exploitable via /cgi-bin/wireless[.]cgi. Public exploit available. Patch released by vendor. #CVE #PatchNow https://t.co/rb81LEQ9L5

    Post summary

    CVE-2026-13539 is a stack-based buffer overflow in Wavlink routers that can be targeted remotely via the /cgi-bin/wireless CGI, with a public exploit available and a vendor-provided patch released.

    0001069
    52 followersView on X
  • VulDB 🛡@vuldb
    General

    A new vulnerability with increased severity was disclosed for Wavlink WL-NU516U1-A (CVE-2026-13539) https://vuldb.com/vuln/374547

    Post summary

    The text reports the disclosure of CVE-2026-13539 for a Wavlink device and notes increased severity, but offers no additional technical details, patches, or exploitation information.

    00010123
    2.2K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-13539 A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the compone… https://www.cve.org/CVERecord?id=CVE-2026-13539 ----- Traducción: Se identificó una … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑13539, identifying a vulnerability in a specific Wavlink device with some technical detail but no evidence of exploitation, PoC, or patch information.

    0000032
    89 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-13539 Stack-Based Buffer Overflow in Wavlink WL-NU516U1-A M16U1_V240425 POST Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13539

    Post summary

    A stack-based buffer overflow vulnerability (CVE-2026-13539) in Wavlink WL-NU516U1-A routers has been disclosed with technical details, but no PoC, exploit, patch, or evidence of active exploitation is provided.

    00000104
    4.1K followersView on X

Explore more