Description
A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin Password Handler. This manipulation causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-08-03
Score: 5.3 Medium
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the set_sys_adm function of the adm.cgi admin password handler on Wavlink WL‑NU516U1. According to the description, improper sanitization of user‑supplied input allows an attacker to inject arbitrary operating‑system commands, effectively granting remote code execution. The weakness corresponds to CWE‑77 and CWE‑78. The impact is the potential compromise of the device, with full control over the underlying firmware and network traffic.

Affected Systems

Affected devices are Wavlink WL‑NU516U1 routers running firmware build 708c073‑mt7628. The vulnerability is triggered by requests to the adm.cgi endpoint used for managing administrator passwords. The vendor has released a fixed firmware version after the issue was reported.

Risk and Exploitability

The CVSS score is 5.3, indicating a moderate severity; EPSS score is 1%, indicating a low probability of exploitation, and the CVE is not listed in the CISA KEV catalog. Public disclosure means the exploit is known to be feasible. An attacker with network access to the router’s administration interface can send crafted input to the set_sys_adm endpoint, potentially executing any OS command. The risk is significant for exposed routers, especially those accessible from the Internet or untrusted networks.

Generated by OpenCVE AI on August 4, 2026 at 21:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest firmware that contains the fix for the command injection in adm.cgi.
  • Restrict or disable remote access to the router’s administrative interface and limit traffic to known trusted IP addresses.
  • Enable logging for administrative actions and review logs regularly to detect abnormal activity.

Generated by OpenCVE AI on August 4, 2026 at 21:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink wl-nu516u1
Vendors & Products Wavlink wl-nu516u1

Mon, 03 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin Password Handler. This manipulation causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title Wavlink WL-NU516U1 Admin Password adm.cgi set_sys_adm os command injection
First Time appeared Wavlink
Wavlink wl-nu516u1 Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:wavlink:wl-nu516u1_firmware:*:*:*:*:*:*:*:*
Vendors & Products Wavlink
Wavlink wl-nu516u1 Firmware
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wavlink Wl-nu516u1 Wl-nu516u1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-03T15:37:14.370Z

Reserved: 2026-08-02T20:33:59.442Z

Link: CVE-2026-18590

cve-icon Vulnrichment

Updated: 2026-08-03T13:47:35.877Z

cve-icon NVD

Status : Deferred

Published: 2026-08-03T08:17:18.613

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-18590

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T21:15:03Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')