CVE-2026-3703 | Wavlink NU516U1 251208 /cgi-bin/login.cgi sub_401A10 ipaddr out-of-bounds write
A vulnerability described as critical has been identified in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to out-of-bounds write.
This vulnerability appears as CVE-2026-3703. The attack may be performed from remote. In addition, an exploit is available.
Upgrading the affected component is recommended.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.