Impact
An OS command injection flaw has been identified in the Config Import component of Wavlink WL-NU516U1 firmware version 708c073-mt7628. Manipulating the Password argument of the unknown function can cause arbitrary system commands to be executed, enabling remote attackers to run code on the device. The vulnerability is remote, requires significant expertise, and an exploit has already been published.
Affected Systems
The flaw impacts Wavlink WL-NU516U1 devices running firmware 708c073-mt7628 (the 708c073-mt7628 build reported by the vendor). No broader version range is listed, so only this build is confirmed to be vulnerable.
Risk and Exploitability
The CVSS score of 7.7 indicates a high‑risk threat, while the EPSS score is 1% and the vulnerability is not included in the CISA KEV catalog. The attack vector is remote and the attack complexity is considered high but the exploit has been published, so the likelihood of exploitation in the wild remains significant. The flaw requires the attacker to manipulate a password field, which may limit ease of exploitation but still poses a severe risk to affected devices.
OpenCVE Enrichment