Impact
The vulnerability is located in the change_wifi_password function of the adm.cgi script on Wavlink NU516U1 routers. By manipulating the wl_channel, wl_Pass, or EncrypType parameters, an attacker may be able to inject arbitrary operating‑system commands. The CVE description does not explicitly state whether authentication is required, so this lack of detail is acknowledged rather than assumed.
Affected Systems
Affected devices are Wavlink NU516U1 routers running firmware M16U1_V240425. No additional version range was provided, but any device with the stated firmware build carries the flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate base severity, yet the nature of OS command injection is high impact. The EPSS score of 5% indicates a moderate probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog; the public disclosure and remote attack surface suggest a tangible risk. The description notes that the attack can be initiated remotely, but it does not explicitly state whether authentication is required, so the risk assessment assumes potential unauthenticated access but acknowledges uncertainty. Exploitation requires network access to the device’s web interface.
OpenCVE Enrichment