Description
A flaw has been found in Wavlink WL-NU516U1 up to 20251208. The affected element is the function singlePortForwardDelete of the file /cgi-bin/firewall.cgi. Executing a manipulation of the argument del_flag can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-02-17
Score: 8.6 High
EPSS: 11.6% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command‑injection vulnerability has been identified in the singlePortForwardDelete function of the /cgi-bin/firewall.cgi file on Wavlink WL‑NU516U1 firmware versions up to 20251208. The flaw abuses improper sanitization of the del_flag argument, enabling an attacker who can send web requests to the device to inject arbitrary shell commands. This leads to remote code execution and full control over the device, potentially exposing sensitive network traffic, altering firewall rules, or disabling the gateway. The weakness is classified as CWE‑74 (Command Injection) and CWE‑77 (Improper Validation of Argument for System or Related API Call).

Affected Systems

The vulnerability impacts Wavlink WL‑NU516U1 units running firmware up to and including version 20251208. Devices with newer firmware are not listed as vulnerable, so only older or identical firmware is affected.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, while the EPSS score of 12% suggests a moderate‑to‑high likelihood of exploitation. The flaw is reachable remotely through the publicly exposed firewall.cgi interface, and exploit code has already been published. Attackers could execute arbitrary commands, disrupt service, or install malicious payloads. Because the vulnerability is not listed in the CISA KEV catalog, organizations should evaluate the exposure of the web interface and apply mitigations proactively.

Generated by OpenCVE AI on August 2, 2026 at 02:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy a firmware update newer than 20251208 that addresses the singlePortForwardDelete injection flaw (when available from Wavlink).
  • Restrict remote access to the firewall.cgi interface by configuring the device’s management settings or blocking the URL path through a perimeter firewall.
  • Disable the singlePortForwardDelete feature or the entire firewall.cgi interface when it is not required, and enforce strict input validation on the del_flag parameter to mitigate injection attempts.

Generated by OpenCVE AI on August 2, 2026 at 02:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 18 Feb 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink wl-nu516u1 Firmware
CPEs cpe:2.3:h:wavlink:wl-nu516u1:-:*:*:*:*:*:*:*
cpe:2.3:o:wavlink:wl-nu516u1_firmware:*:*:*:*:*:*:*:*
Vendors & Products Wavlink wl-nu516u1 Firmware

Wed, 18 Feb 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 18 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink
Wavlink wl-nu516u1
Vendors & Products Wavlink
Wavlink wl-nu516u1

Tue, 17 Feb 2026 13:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Wavlink WL-NU516U1 up to 20251208. The affected element is the function singlePortForwardDelete of the file /cgi-bin/firewall.cgi. Executing a manipulation of the argument del_flag can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Wavlink WL-NU516U1 firewall.cgi singlePortForwardDelete command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wavlink Wl-nu516u1 Wl-nu516u1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T10:13:22.556Z

Reserved: 2026-02-17T06:53:05.788Z

Link: CVE-2026-2615

cve-icon Vulnrichment

Updated: 2026-02-17T14:16:29.888Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-17T13:16:17.113

Modified: 2026-06-17T10:31:23.970

Link: CVE-2026-2615

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T02:45:03Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')