A critical vulnerability (CVE-2026-74843) has been disclosed in Wavlink WN531P3 and WN535M1 V250922 devices. The flaw resides in the export_pingortrace.cgi component, which uses the strcpy function without proper bounds checking on the HTTP_COOKIE argument. This allows remote attackers to trigger a stack-based buffer overflow, potentially leading to arbitrary code execution with elevated privileges. The vulnerability impacts devices running the lighttpd web server platform and is exploitable over HTTP without requiring authentication. Affected versions include Wavlink WN531P3 and WN535M1 firmware releases prior to an unspecified patched version. Exploits leveraging this vulnerability are publicly available, significantly increasing the risk of targeted attacks. Organizations deploying these devices should prioritize applying vendor-provided security updates, implementing strict input validation for HTTP requests, and monitoring network traffic for anomalous activity. Given the CVSS score of 10.0 and the availability of working exploits, this vulnerability requires immediate remediation to prevent potential large-scale compromises.
CRITICAL
CVSS 10.0
CVE-2026-74843
2026-08-19
Critical Remote Code Execution Vulnerability in Wavlink Devices (CVE-2026-74843)
A critical remote code execution vulnerability (CVE-2026-74843) affects Wavlink WN531P3 and WN535M1 devices due to a stack-based buffer overflow in the export_pingortrace.cgi CGI script. Exploitation allows remote attackers to execute arbitrary code. Immediate mitigation is required.