Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Wavlink WN531P3/WN535M1 Export Pingortrace CGI export_pingortrace.cgi strcpy stack-based overflow
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 9.3 .0097 59.1 —
AFFECTED
Product Versions Fixed
WN531P3 V250922 – —
WN535M1 V250922 – —
TIMELINE
Aug 16 EXPLOIT PUBLISHED — CVE-2026-74843 (Wavlink WN531P3). Public exploit reference added.
Aug 17 Reserved by VulDB
Aug 17 Published (CNA: VulDB)
Description
A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the component Export Pingortrace CGI. Executing a manipulation of the argument HTTP_COOKIE can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 16, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-74843 (Wavlink WN531P3). Public exploit reference added. |
| August 17, 2026 | Reserved | Reserved by VulDB |
| August 17, 2026 | Published | Published (CNA: VulDB) |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Wavlink | WN531P3 | — | V250922 | — |
| Wavlink | WN535M1 | — | V250922 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-74843 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.