U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2026-18607

Change History

New CVE Received from VulDB 8/03/2026 1:16:35 PM

Action Type Old Value New Value
Added Description

                  
                
              
A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd. The manipulation of the argument HTTP_COOKIE leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Added CVSS V4.0

                  
                
              
AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Added CVSS V3.1

                  
                
              
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Added CVSS V2

                  
                
              
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Added CWE

                  
                
              
CWE-119
Added CWE

                  
                
              
CWE-121
Added Reference

                  
                
              
https://github.com/0xcc12138/WAVLINK-vul
Added Reference

                  
                
              
https://vuldb.com/cve/CVE-2026-18607
Added Reference

                  
                
              
https://vuldb.com/submit/852637
Added Reference

                  
                
              
https://vuldb.com/vuln/385530
Added Reference

                  
                
              
https://vuldb.com/vuln/385530/cti
Added Affected

                  
                
              
[{"vendor":"Wavlink","product":"WN572","cpes":["cpe:2.3:a:wavlink:wn572:*:*:*:*:*:*:*:*"],"modules":["lighttpd"],"versions":[{"version":"20260609","status":"affected"}]},{"vendor":"Wavlink","product":"WN570H","cpes":["cpe:2.3:a:wavlink:wn570h:*:*:*:*:*:*:*:*"],"modules":["lighttpd"],"versions":[{"version":"20260609","status":"affected"}]},{"vendor":"Wavlink","product":"WN573","cpes":["cpe:2.3:a:wavlink:wn573:*:*:*:*:*:*:*:*"],"modules":["lighttpd"],"versions":[{"version":"20260609","status":"affected"}]},{"vendor":"Wavlink","product":"WN529","cpes":["cpe:2.3:a:wavlink:wn529:*:*:*:*:*:*:*:*"],"modules":["lighttpd"],"versions":[{"version":"20260609","status":"affected"}]},{"vendor":"Wavlink","product":"WN530","cpes":["cpe:2.3:a:wavlink:wn530:*:*:*:*:*:*:*:*"],"modules":["lighttpd"],"versions":[{"version":"20260609","status":"affected"}]},{"vendor":"Wavlink","product":"WN531","cpes":["cpe:2.3:a:wavlink:wn531:*:*:*:*:*:*:*:*"],"modules":["lighttpd"],"versions":[{"version":"20260609","status":"affected"}]},{"vendor":"Wavlink","product":"WN535","cpes":["cpe:2.3:a:wavlink:wn535:*:*:*:*:*:*:*:*"],"modules":["lighttpd"],"versions":[{"version":"20260609","status":"affected"}]},{"vendor":"Wavlink","product":"etc. WN529","cpes":["cpe:2.3:a:wavlink:etc._wn529:*:*:*:*:*:*:*:*"],"modules":["lighttpd"],"versions":[{"version":"20260609","status":"affected"}]},{"vendor":"Wavlink","product":"WN530","cpes":["cpe:2.3:a:wavlink:wn530:*:*:*:*:*:*:*:*"],"modules":["lighttpd"],"versions":[{"version":"20260609","status":"affected"}]},{"vendor":"Wavlink","product":"WN531","cpes":["cpe:2.3:a:wavlink:wn531:*:*:*:*:*:*:*:*"],"modules":["lighttpd"],"versions":[{"version":"20260609","status":"affected"}]},{"vendor":"Wavlink","product":"WN535","cpes":["cpe:2.3:a:wavlink:wn535:*:*:*:*:*:*:*:*"],"modules":["lighttpd"],"versions":[{"version":"20260609","status":"affected"}]},{"vendor":"Wavlink","product":"WN536","cpes":["cpe:2.3:a:wavlink:wn536:*:*:*:*:*:*:*:*"],"modules":["lighttpd"],"versions":[{"version":"20260609","status":"affected"}]},{"vendor":"Wavlink","product":"WN551","cpes":["cpe:2.3:a:wavlink:wn551:*:*:*:*:*:*:*:*"],"modules":["lighttpd"],"versions":[{"version":"20260609","status":"affected"}]},{"vendor":"Wavlink","product":"WN557","cpes":["cpe:2.3:a:wavlink:wn557:*:*:*:*:*:*:*:*"],"modules":["lighttpd"],"versions":[{"version":"20260609","status":"affected"}]},{"vendor":"Wavlink","product":"NU516","cpes":["cpe:2.3:a:wavlink:nu516:*:*:*:*:*:*:*:*"],"modules":["lighttpd"],"versions":[{"version":"20260609","status":"affected"}]}]