{"id":"CVE-2026-74843","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-74843","summary":"A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi…","details":"A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the component Export Pingortrace CGI. Executing a manipulation of the argument HTTP_COOKIE can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.","published":"2026-08-17T12:18:58.180","modified":"2026-08-17T12:18:58.180","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/wcndsb-sketch/WAVLINK_WN535M1-M35M1_V250922-Buffer-Overflow/blob/main/CVE-Report-WAVLINK-WN535M1-RCE.pdf"},{"type":"WEB","url":"https://vuldb.com/cve/CVE-2026-74843"},{"type":"WEB","url":"https://vuldb.com/submit/875331"},{"type":"WEB","url":"https://vuldb.com/vuln/391205"},{"type":"WEB","url":"https://vuldb.com/vuln/391205/cti"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-17T12:18:58.180"}}