Vendor
critical
advisory
Unauthenticated Arbitrary File Write in WAVLINK Routers
2 TTPs 1 CVEWAVLINK WN535M1 and WN535M3 routers are vulnerable to unauthenticated arbitrary file writes via the sync_server daemon, enabling attackers to gain root-level persistence.
WN535M1 +1
network-security
remote-code-execution
cve-2026-89009
2t
1c
critical
advisory
Critical Buffer Overflow in Wavlink Router Export Pingortrace CGI
1 rule 1 TTP 1 CVEA critical stack-based buffer overflow in Wavlink WN531P3 and WN535M1 devices allows remote code execution via crafted HTTP cookie data.
WN531P3 +1
cve-2026-74843
rce
buffer-overflow
network-appliance
1r
1t
1c
high
advisory
Remote Stack-Based Buffer Overflow in Wavlink Networking Devices
1 TTP 1 CVE 1 IOCMultiple Wavlink networking devices are vulnerable to a remote stack-based buffer overflow in the lighttpd component due to insecure use of strcpy in the upload.cgi script via the HTTP_COOKIE header.
WN572 +10
vulnerability
rce
network-infrastructure
1t
1c
1i
critical
advisory
Stack-based Buffer Overflow in Wavlink WL-NU516U1 nas.cgi
4 TTPs 1 CVEA stack-based buffer overflow vulnerability in the nas.cgi file of Wavlink WL-NU516U1 routers allows remote, unauthenticated attackers to execute arbitrary code via a malicious CONTENT_LENGTH argument.
WL-NU516U1 +1
cve-2026-18589
buffer-overflow
router
rce
4t
1c