← Back to Research Blog
CRITICAL CVE-2026-74843

Critical Remote Code Execution Vulnerability in Wavlink SOHO Routers: CVE-2026-74843 Exploited in the Wild

10.0
CRITICAL
export_pingortrace.cgi, lighttpd, wavlin
2026-08-19

Overview

CVE-2026-74843 is a CVSS 10.0 stack-based buffer overflow vulnerability in Wavlink WN531P3/535M1 routers, enabling unauthenticated remote code execution via manipulated HTTP_COOKIE headers. Public exploits exist, necessitating immediate remediation for affected devices in enterprise and DIB networks.


Technical Analysis

The vulnerability stems from unchecked use of strcpy() in the export_pingortrace.cgi CGI script, which processes the HTTP_COOKIE header without length validation. Attackers can craft oversized cookies to overwrite the stack and execute arbitrary code with no authentication required. Exploitation requires a single malicious HTTP request to the /cgi-bin/export_pingortrace.cgi endpoint, with no user interaction beyond device network accessibility. The exploit chain is fully remote, leveraging common lighttpd CGI execution patterns.

Enterprise & DIB Impact

While these devices are marketed as consumer-grade, DIB and enterprise environments may deploy them in remote office or IoT architectures, creating potential attack surfaces for supply chain interception or lateral network compromise. The publicly available PoC lowers barriers for scripted scanning campaigns targeting weakly monitored SOHO infrastructure.

Recommended Actions

Need Help Assessing Your Exposure?

Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.

Schedule a Consultation
Full security advisory on 247alerts.net →
Axiom Cyber Research
Axiom Cyber Research, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing elite cybersecurity consulting to the Defense Industrial Base and regulated sectors. Founded by a 20+ year veteran with deep offensive and defensive cyber expertise. Our CVE intelligence program actively tracks emerging vulnerabilities to help organizations prioritize remediation and reduce exposure windows.
Baltimore, MD  ·  axiomcyber.io  ·  247alerts.net  ·  SDVOSB  ·  NAICS 541512