Vulnerability Description
A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the component Export Pingortrace CGI. Executing a manipulation of the argument HTTP_COOKIE can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/wcndsb-sketch/WAVLINK_WN535M1-M35M1_V250922-Buffer-Overflow/b
- https://vuldb.com/cve/CVE-2026-74843
- https://vuldb.com/submit/875331
- https://vuldb.com/vuln/391205
- https://vuldb.com/vuln/391205/cti
FAQ
What is CVE-2026-74843?
CVE-2026-74843 is a vulnerability with a CVSS score of 10.0 (CRITICAL). A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the compone...
How severe is CVE-2026-74843?
CVE-2026-74843 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-74843?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.