A critical vulnerability (CVE-2026-74843) has been disclosed in Wavlink WN531P3 and WN535M1 V250922 devices. The flaw resides in the export_pingortrace.cgi component, which uses the strcpy function without proper bounds checking on the HTTP_COOKIE argument. This allows remote attackers to trigger a stack-based buffer overflow, potentially leading to arbitrary code execution with elevated privileges. The vulnerability impacts devices running the lighttpd web server platform and is exploitable over HTTP without requiring authentication. Affected versions include Wavlink WN531P3 and WN535M1 firmware releases prior to an unspecified patched version. Exploits leveraging this vulnerability are publicly available, significantly increasing the risk of targeted attacks. Organizations deploying these devices should prioritize applying vendor-provided security updates, implementing strict input validation for HTTP requests, and monitoring network traffic for anomalous activity. Given the CVSS score of 10.0 and the availability of working exploits, this vulnerability requires immediate remediation to prevent potential large-scale compromises.