CVE-2026-2566Disclosure

LOWCVSS 7.3 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in Wavlink WL-NU516U1 up to 130/260. This affects the function sub_406194 of the file /cgi-bin/adm.cgi. Such manipulation of the argument firmware_url leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-16: 3Patch / Workaround · 2026-02-16: 1Technical Details · 2026-02-16: 302-16
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2566 Wavlink WL-NU516U1 Remote Stack Overflow Vulnerability in Firmware... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2566 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A brief alert announces CVE-2026-2566 as a remote stack overflow in Wavlink WL-NU516U1 firmware, linking to a vulnerability details page, but it does not provide a PoC, exploit, or patch information.

    0000036
    4.0K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH-severity alert: Stack overflow in Wavlink WL-NU516U1 routers (fw ≤130/260) allows remote takeover — no patch yet! Disable remote mgmt & segment networks now. European orgs at risk. Details: https://radar.offseq.com/threat/cve-2026-2566-stack-based-buffer-overflow-in-wav... https://t.co/1SSgf3zsLH

    Post summary

    The tweet warns of a high‑severity stack overflow in Wavlink WL‑NU516U1 routers that enables remote takeover; no patch exists yet, so it recommends disabling remote management and segmenting networks to mitigate the risk.

    0000036
    265 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2566 A security vulnerability has been detected in Wavlink WL-NU516U1 up to 130/260. This affects the function sub_406194 of the file /cgi-bin/adm.cgi. Such manipulation of … https://www.cve.org/CVERecord?id=CVE-2026-2566

    Post summary

    A vulnerability (CVE-2026-2566) affecting the function sub_406194 in /cgi-bin/adm.cgi of Wavlink WL-NU516U1 routers up to firmware 130/260 has been identified. No PoC, exploit, patch, or active exploitation is reported.

    00000502
    56.4K followersView on X

Explore more