Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6rfc-r3c7-7f5j

Опубликовано: 08 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.9
CVSS3: 9.8

Описание

A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to out-of-bounds write. The attack may be performed from remote. The exploit has been published and may be used. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to out-of-bounds write. The attack may be performed from remote. The exploit has been published and may be used. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

EPSS

Процентиль: 43%
0.00208
Низкий

8.9 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 месяца назад

A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to out-of-bounds write. The attack may be performed from remote. The exploit has been published and may be used. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

EPSS

Процентиль: 43%
0.00208
Низкий

8.9 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-119