Description
A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the file /cgi-bin/adm.cgi. The manipulation of the argument wl_channel/wl_Pass/EncrypType leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.
Published: 2026-05-09
Score: 5.3 Medium
EPSS: 5.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is located in the change_wifi_password function of the adm.cgi script on Wavlink NU516U1 routers. By manipulating the wl_channel, wl_Pass, or EncrypType parameters, an attacker may be able to inject arbitrary operating‑system commands. The CVE description does not explicitly state whether authentication is required, so this lack of detail is acknowledged rather than assumed.

Affected Systems

Affected devices are Wavlink NU516U1 routers running firmware M16U1_V240425. No additional version range was provided, but any device with the stated firmware build carries the flaw.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate base severity, yet the nature of OS command injection is high impact. The EPSS score of 5% indicates a moderate probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog; the public disclosure and remote attack surface suggest a tangible risk. The description notes that the attack can be initiated remotely, but it does not explicitly state whether authentication is required, so the risk assessment assumes potential unauthenticated access but acknowledges uncertainty. Exploitation requires network access to the device’s web interface.

Generated by OpenCVE AI on June 18, 2026 at 13:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware that removes the command‑injection flaw on Wavlink NU516U1 routers.
  • Restrict access to the /cgi‑bin/adm.cgi administrative interface to the local network or a trusted management VLAN.
  • Disable or remove the ability to change the Wi‑Fi password via the web interface, or restrict that capability to privileged users through access control.

Generated by OpenCVE AI on June 18, 2026 at 13:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink wl-nu516u1 Firmware
CPEs cpe:2.3:h:wavlink:wl-nu516u1:-:*:*:*:*:*:*:*
cpe:2.3:o:wavlink:wl-nu516u1_firmware:m16u1_v240425:*:*:*:*:*:*:*
Vendors & Products Wavlink wl-nu516u1 Firmware

Mon, 11 May 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 10 May 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink
Wavlink wl-nu516u1
Vendors & Products Wavlink
Wavlink wl-nu516u1

Sat, 09 May 2026 15:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the file /cgi-bin/adm.cgi. The manipulation of the argument wl_channel/wl_Pass/EncrypType leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.
Title Wavlink NU516U1 adm.cgi change_wifi_password os command injection
Weaknesses CWE-77
CWE-78
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wavlink Wl-nu516u1 Wl-nu516u1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-11T17:32:10.946Z

Reserved: 2026-05-08T19:52:02.937Z

Link: CVE-2026-8188

cve-icon Vulnrichment

Updated: 2026-05-11T16:03:54.673Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-09T16:16:08.870

Modified: 2026-06-17T11:03:35.890

Link: CVE-2026-8188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T13:15:15Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')