CVE-2026-3703Disclosure(wavlink / wl-nu516u1)

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch wavlink wl-nu516u1 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to out-of-bounds write. The attack may be performed from remote. The exploit has been published and may be used. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wl-nu516u1
  • wl-nu516u1_firmware

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 10 signals
  • Disclosure: 5 classified signals
  • Peaked 4d ago at 6 mentions (2026-03-08); latest day: 1
  • 11 total mentions across 6 days

Affected systems

Vendors
Products
wl-nu516u1wl-nu516u1_firmware

2 versions affected across 2 products

Deep dive

Activity timeline11 mentions / 6d
02356Mentions · 2026-03-07: 1Mentions · 2026-03-08: 6Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1PoC Mentioned / Linked · 2026-03-08: 2PoC Mentioned / Linked · 2026-03-09: 1PoC Mentioned / Linked · 2026-03-10: 1Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-08: 6Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 103-0703-0803-0903-1003-1203-13
Signal classification4 categories
Disclosure
545.5%
Patch
327.3%
PoC
218.2%
General
19.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-071
General1
2026-03-086
Disclosure3Patch1PoC2
2026-03-091
Patch1
2026-03-101
Patch1
2026-03-121
Disclosure1
2026-03-131
Disclosure1
Full discourse11 posts
  • maru@maru1151157
    Patch

    🚨 CVE-2026-3703 (CVSS: 9.8) Wavlink NU516U1の/cgi-bin/login.cgi内のsub_401A10関数で、ipaddr引数の操作によりOut-of-Bounds Writeが発生し、リモートからの攻撃可能。エクスプロイトが公開されているため、対象コンポーネントのアップグレードを推奨。 https://maruomosquit.com/vulnerability/CVE-2026-3703/ #脆弱性 #セキュリティ

    Post summary

    CVE-2026-3703 is a high‑severity Out‑of‑Bounds Write vulnerability in Wavlink NU516U1, with publicly available exploit code; the affected component should be upgraded.

    00040116
    1.7K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3703 (CVSS:8.9, CRITICAL) is Analyzed. A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Ex..https://nvd.nist.gov/vuln/detail/CVE-2026-3703 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The statement announces CVE-2026-3703 as a critical flaw in Wavlink NU516U1’s login.cgi with technical details, but no PoC, exploitation evidence, patch, or false‑positive claim is provided.

    0000024
    172 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3703 (CVSS:8.9, CRITICAL) is Analyzed. A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Ex..https://nvd.nist.gov/vuln/detail/CVE-2026-3703 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post describes a newly analyzed critical vulnerability (CVE‑2026‑3703) in a Wavlink device, providing technical details but no exploitation or patch information.

    0000024
    172 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Wavlink NU516U1 router (CVSS 9.8-9.8) Affected: Wavlink NU516U1 Internet-facing risks dominate, driven by a remote-exploitation flaw in the Wavlink NU516U1 router; fixes and mitigations below. CVE-2026-3703 (CVSS 9.8) Wavlink NU516U1 devices with firmware 251208 are affected by a vulnerability in /cgi-bin/login.cgi sub_401A10 that allows manipulation of the ipaddr argument to trigger an out-of-bounds write; a publicly released exploit enables remote exploitation, and upgrading to the fixed version is recommended. 🛠️ Action • Patch/upgrade to the fixed version released by the vendor • Prioritize internet-facing instances and edge appliances first • If no fix yet, apply mitigations and reduce exposure (disable affected feature, restrict access) • Add detections for exploitation patterns (abnormal requests to /cgi-bin/login.cgi with crafted ipaddr values; look for webshell/file-write activity) • Hunt for indicators across logs/EDR/WAF from disclosure to now • Validate remediation (version/config checks) and monitor for reversion

    Post summary

    The post discloses a critical CVE-2026-3703 flaw in Wavlink NU516U1 routers that allows remote exploitation via a public exploit, and it provides vendor patch guidance and mitigations.

    0000057
    85 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3703 A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr ca… https://www.cve.org/CVERecord?id=CVE-2026-3703

    Post summary

    CVE-2026‑3703 is a newly disclosed flaw affecting Wavlink NU516U1's /cgi-bin/login.cgi sub_401A10 via manipulation of the ipaddr argument; no PoC, exploit, or patch information is provided.

    00000111
    56.6K followersView on X
  • Vivek | ThreatIntel@VivekIntel
    PoC

    CVE-2026-3703: Critical RCE in Wavlink NU516U1 routers A critical vulnerability affecting Wavlink NU516U1 (firmware 251208) allows remote attackers to execute arbitrary code via the device’s web management interface. The flaw resides in /cgi-bin/login.cgi, where improper handling of the ipaddr parameter leads to an out-of-bounds write, enabling memory corruption. Key details: • CVE: CVE-2026-3703 • CVSS: 9.8 (Critical) • Attack vector: network-accessible web interface • Auth: not required • Exploit: public PoC available Successful exploitation could allow attackers to gain full control of the device, deploy malware, or pivot into internal networks. Devices with remote management exposed are at the highest risk. Source https://www.yazoul.net/advisory/cve/cve-2026-3703 #CyberSecurity #ThreatIntel #CVE #Vulnerability

    Post summary

    The advisory discloses a critical RCE in Wavlink NU516U1 routers, confirms a public PoC is available, but does not mention a patch, workaround, or active exploitation.

    0000072
    193 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-3703 - Critical A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to out-of-bou... https://www.thehackerwire.com/vulnerability/CVE-2026-3703/ https://t.co/NkEbzYo9vh

    Post summary

    A critical flaw was discovered in Wavlink NU516U1, impacting the login CGI; manipulating the ipaddr argument may trigger an out‑of‑bounds condition.

    0000035
    130 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3703 Wavlink NU516U1 Remote Out-of-Bounds Write Vulnerability in Login CGI https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3703

    Post summary

    The entry announces CVE-2026-3703, identifying it as a remote out‑of‑bounds write flaw in Wavlink NU516U1’s login CGI, and provides a link for further details.

    0000040
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-3703: CRITICAL] Critical security flaw found in Wavlink NU516U1 251208 can lead to remote attacks by manipulating ipaddr argument in /cgi-bin/login.cgi. Ensure to update affected component.#cve,CVE-2026-3703,#cybersecurity https://cvefind.com/CVE-2026-3703

    Post summary

    The post alerts to a critical flaw in a Wavlink device that could enable remote attacks and urges users to apply a patch or update.

    0000052
    600 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-3703: Wav... Buffer overflow in Wavlink's login.cgi via ipaddr param - unauthenticated RCE with public exploit makes this router pwned by default. #RouterPwn #RCE. https://zerodaysignal.com/vulnerability/CVE-2026-3703 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    Wavlink routers suffer a buffer overflow in login.cgi that allows unauthenticated RCE, and a public exploit is available.

    0000097
    140 followersView on X
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting Wavlink NU516U1 (CVE-2026-3703) https://vuldb.com/?id.349649

    Post summary

    The post merely notes an increased severity rating for CVE-2026-3703 on the Wavlink NU516U1 device, without providing PoC, exploit, patch, or technical detail information.

    00000113
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWwavlinkwl-nu516u1---
OSwavlinkwl-nu516u1_firmware251208--

Explore more