Description
A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of the argument Password can lead to os command injection. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is regarded as difficult. The exploit has been published and may be used. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-08-03
Score: 7.7 High
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS command injection flaw has been identified in the Config Import component of Wavlink WL-NU516U1 firmware version 708c073-mt7628. Manipulating the Password argument of the unknown function can cause arbitrary system commands to be executed, enabling remote attackers to run code on the device. The vulnerability is remote, requires significant expertise, and an exploit has already been published.

Affected Systems

The flaw impacts Wavlink WL-NU516U1 devices running firmware 708c073-mt7628 (the 708c073-mt7628 build reported by the vendor). No broader version range is listed, so only this build is confirmed to be vulnerable.

Risk and Exploitability

The CVSS score of 7.7 indicates a high‑risk threat, while the EPSS score is 1% and the vulnerability is not included in the CISA KEV catalog. The attack vector is remote and the attack complexity is considered high but the exploit has been published, so the likelihood of exploitation in the wild remains significant. The flaw requires the attacker to manipulate a password field, which may limit ease of exploitation but still poses a severe risk to affected devices.

Generated by OpenCVE AI on August 4, 2026 at 10:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor provided firmware upgrade that fixes the command injection flaw; the updated image is available on Wavlink’s official download page.
  • If a firmware upgrade cannot be performed immediately, block or restrict access to the Config Import functionality or the device’s web management interface to prevent exploitation.
  • Monitor system logs for signs of unexpected command execution and enforce least privilege on administrative accounts to limit potential impact if compromise occurs.

Generated by OpenCVE AI on August 4, 2026 at 10:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink wl-nu516u1
Vendors & Products Wavlink wl-nu516u1

Mon, 03 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of the argument Password can lead to os command injection. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is regarded as difficult. The exploit has been published and may be used. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title Wavlink WL-NU516U1 Config Import os command injection
First Time appeared Wavlink
Wavlink wl-nu516u1 Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:wavlink:wl-nu516u1_firmware:*:*:*:*:*:*:*:*
Vendors & Products Wavlink
Wavlink wl-nu516u1 Firmware
References
Metrics cvssV2_0

{'score': 7.6, 'vector': 'AV:N/AC:H/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wavlink Wl-nu516u1 Wl-nu516u1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-03T20:16:37.670Z

Reserved: 2026-08-02T20:33:24.850Z

Link: CVE-2026-18587

cve-icon Vulnrichment

Updated: 2026-08-03T20:15:54.971Z

cve-icon NVD

Status : Deferred

Published: 2026-08-03T07:16:42.813

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-18587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T10:45:05Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')