CVE-2026-74843Disclosure

MEDIUMCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the component Export Pingortrace CGI. Executing a manipulation of the argument HTTP_COOKIE can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-08-17); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01223Mentions · 2026-08-17: 3Mentions · 2026-08-18: 3Mentions · 2026-08-19: 1PoC Mentioned / Linked · 2026-08-17: 1PoC Mentioned / Linked · 2026-08-18: 1Active Exploitation · 2026-08-18: 1Technical Details · 2026-08-17: 2Technical Details · 2026-08-18: 1Technical Details · 2026-08-19: 108-1708-1808-19
Signal classification4 categories
Disclosure
342.9%
PoC
228.6%
Active Exploitation
114.3%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-173
Disclosure2PoC1
2026-08-183
Active Exploitation1General1PoC1
2026-08-191
Disclosure1
Full discourse7 posts
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-19478 - EXPLOIT CVE-2026-71518 - EXPLOIT CVE-2026-74253 CVE-2026-74843 CVE-2026-47686 ..🧵👇

    Post summary

    The post lists several CVEs, some marked as "EXploIT", but provides no further technical or contextual information.

    1103073
    62 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    📡 Wavlink WN531P3/WN535M1: critical stack overflow via strcpy in export_pingortrace.cgi, CVSS 9.3, no auth required, network-exploitable. CVE-2026-74843 — check your firmware. #cybersecurity #ciso #cto #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-74843?utm_campaign=x https://t.co/iWm8VJWm4F

    Post summary

    Wavlink WN531P3/WN535M1 routers suffer a critical stack overflow (CVE‑2026‑74843) that is network‑exploitable with no authentication; users are urged to check for firmware updates.

    01010151
    880 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2026-74843 [HIGH PRIORITY] #Wavlink WN531P3/WN535M1 Export Pingortrace CGI export_pingortrace.cgi strcpy ... 🔗 https://exploitgrid.net/cve/CVE-2026-74843

    Post summary

    CVE-2026-74843 is a high-priority buffer overflow flaw in Wavlink routers, with a PoC linked on Exploitgrid; no evidence of active exploitation or patched remediation is provided.

    1000033
    33 followersView on X
  • Upwind Security MDR@UpwindMDR
    PoC

    🚨Critical - Wavlink Export Pingortrace CGI Stack Buffer Overflow RCE (CVE-2026-74843) Wavlink WN531P3/WN535M1 V250922 export_pingortrace.cgi (/etc/lighttpd/www/cgi-bin/export_pingortrace.cgi) uses unsafe strcpy on HTTP_COOKIE, enabling a remote attacker to overflow the stack via a crafted Cookie header and potentially achieve RCE/crash. Public exploit info is available. 👉Affected: Wavlink WN531P3, WN535M1 firmware V250922

    Post summary

    The post announces a critical stack buffer overflow (CVE‑2026‑74843) in Wavlink routers, confirms a public proof‑of‑concept exploit exists, but provides no evidence of active exploitation or patch information.

    00010108
    291 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting Wavlink WN531P3 and WN535M1 (CVE-2026-74843) https://vuldb.com/vuln/391205/cti

    Post summary

    CTI reports numerous attack attempts against Wavlink devices affected by CVE‑2026‑74843, indicating active exploitation, but no patches or detailed technical info are supplied.

    00000119
    2.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-74843 Stack-Based Buffer Overflow in Wavlink WN531P3/WN535M1 vi... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-74843 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A stack-based buffer overflow vulnerability (CVE‑2026‑74843) affecting Wavlink WN531P3/WN535M1 devices has been disclosed, but no PoC, exploit code, active exploitation or patch information is provided.

    0000098
    4.1K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Wavlink WN531P3 and WN535M1 (CVE-2026-74843) https://vuldb.com/vuln/391205

    Post summary

    The post announces the addition of a new vulnerability (CVE‑2026‑74843) for specific Wavlink devices, linking to a vulnerability database entry.

    00000162
    2.3K followersView on X

Explore more