Impact
A security flaw in the WL‑NU516U1 firmware allows remote attackers to inject OS commands via the ‘lan_ip’ parameter in the wlink_uci_set_value function, which is invoked by adm.cgi. This enables execution on the device, giving attackers full control over the router’s operating system. The affected code accepts unvalidated user input and passes it directly to the shell, exposing the device to command injection (CWE‑78) and broader input‑validation weaknesses (CWE‑77).
Affected Systems
Devices manufactured by Wavlink under the product line WL‑NU516U1, running firmware version 260515, are impacted. The vulnerability resides in the adm.cgi component of the router’s web interface. Firmware releases after 260515 that include the vendor patch resolve the issue; any device still on the original firmware is susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity vulnerability that could lead to significant loss of confidentiality, integrity, and availability if exploited. The EPSS score of 1 % suggests that while exploitation likelihood is low, it is non‑zero, and public exploits are available. The vulnerability is not listed in CISA’s KEV catalog; however, attackers could still target remotely, especially if the router’s web interface is exposed to the internet. Immediate patching is advised to eliminate the remote command injection vector.
OpenCVE Enrichment