Impact
A command‑injection vulnerability has been identified in the singlePortForwardDelete function of the /cgi-bin/firewall.cgi file on Wavlink WL‑NU516U1 firmware versions up to 20251208. The flaw abuses improper sanitization of the del_flag argument, enabling an attacker who can send web requests to the device to inject arbitrary shell commands. This leads to remote code execution and full control over the device, potentially exposing sensitive network traffic, altering firewall rules, or disabling the gateway. The weakness is classified as CWE‑74 (Command Injection) and CWE‑77 (Improper Validation of Argument for System or Related API Call).
Affected Systems
The vulnerability impacts Wavlink WL‑NU516U1 units running firmware up to and including version 20251208. Devices with newer firmware are not listed as vulnerable, so only older or identical firmware is affected.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of 12% suggests a moderate‑to‑high likelihood of exploitation. The flaw is reachable remotely through the publicly exposed firewall.cgi interface, and exploit code has already been published. Attackers could execute arbitrary commands, disrupt service, or install malicious payloads. Because the vulnerability is not listed in the CISA KEV catalog, organizations should evaluate the exposure of the web interface and apply mitigations proactively.
OpenCVE Enrichment