Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-30386 | A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_4012A0 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 07 Oct 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wavlink wl-nu516u1 Firmware
|
|
CPEs | cpe:2.3:h:wavlink:wl-nu516u1:-:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wl-nu516u1_firmware:m16u1_v240425:*:*:*:*:*:*:* |
|
Vendors & Products |
Wavlink wl-nu516u1 Firmware
|
Mon, 22 Sep 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 22 Sep 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wavlink
Wavlink wl-nu516u1 |
|
Vendors & Products |
Wavlink
Wavlink wl-nu516u1 |
Mon, 22 Sep 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_4012A0 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Wavlink WL-NU516U1 login.cgi sub_4012A0 os command injection | |
Weaknesses | CWE-77 CWE-78 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-22T16:12:51.103Z
Reserved: 2025-09-21T08:30:24.929Z
Link: CVE-2025-10775

Updated: 2025-09-22T16:12:40.909Z

Status : Analyzed
Published: 2025-09-22T01:15:36.260
Modified: 2025-10-07T20:47:40.273
Link: CVE-2025-10775

No data.

Updated: 2025-09-22T09:58:39Z