CVE-2026-2567PoC(wavlink / wl-nu516u1)

LOWCVSS 7.3 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in Wavlink WL-NU516U1 20251208. This vulnerability affects the function sub_401218 of the file /cgi-bin/nas.cgi. Performing a manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wl-nu516u1
  • wl-nu516u1_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
wl-nu516u1wl-nu516u1_firmware

1 version affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-16: 1PoC Mentioned / Linked · 2026-02-16: 1Technical Details · 2026-02-16: 102-16
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
Full discourse1 post
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    PoC

    🚨 HIGH severity alert: CVE-2026-2567 impacts Wavlink WL-NU516U1 (20251208) via stack buffer overflow in /cgi-bin/nas.cgi. Public exploit exists — restrict admin access & monitor now! 🔒 https://radar.offseq.com/threat/cve-2026-2567-stack-based-buffer-overflow-in-wavli-0c1e9353 ... https://t.co/0cOaXg9jK9

    Post summary

    The tweet alerts to a high‑severity stack buffer overflow CVE‑2026‑2567 in Wavlink routers, noting that a public exploit exists and urging administrators to restrict access and monitor for activity.

    0000038
    265 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWwavlinkwl-nu516u1---
OSwavlinkwl-nu516u1_firmware---

Explore more