CVE-2026-4861Disclosure(wavlink / wl-nu516u1)

LOWCVSS 7.4 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in Wavlink WL-NU516U1 260227. This vulnerability affects the function ftext of the file /cgi-bin/nas.cgi. This manipulation of the argument Content-Length causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wl-nu516u1
  • wl-nu516u1_firmware

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
wl-nu516u1wl-nu516u1_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-26: 3Technical Details · 2026-03-26: 303-26
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4861 A weakness has been identified in Wavlink WL-NU516U1 260227. This vulnerability affects the function ftext of the file /cgi-bin/nas.cgi. This manipulation of the argume… https://www.cve.org/CVERecord?id=CVE-2026-4861

    Post summary

    A brief disclosure that CVE-2026-4861 is a weakness in the Wavlink WL-NU516U1 device affecting function ftext, with no PoC, exploit, patch, or exploitation claim provided.

    0000082
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4861 - Wavlink WL-NU516U1 nas.cgi ftext stack-based overflow Intel Report: https://ift.tt/BvTCHXA

    Post summary

    An alert announces CVE-2026-4861, a stack-based overflow in Wavlink WL-NU516U1 nas.cgi ftext, and provides a link to an Intel report.

    0000026
    286 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4861: HIGH] Vulnerability found in Wavlink WL-NU516U1 260227's ftext function, allowing remote exploitation via stack-based buffer overflow triggered by Content-Length argument manipulation.#cve,CVE-2026-4861,#cybersecurity https://cvefind.com/CVE-2026-4861

    Post summary

    The post reveals CVE‑2026‑4861, a high‑severity stack buffer overflow in Wavlink WL‑NU516U1’s ftext function triggered by a rogue Content‑Length header, but it does not provide PoC, exploit code, active usage, patches, or any false‑positive claim.

    0000046
    606 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWwavlinkwl-nu516u1---
OSwavlinkwl-nu516u1_firmwarem16u1_v260227--

Explore more