Description
A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the file /cgi-bin/adm.cgi. The manipulation of the argument wl_channel/wl_Pass/EncrypType leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.
Published: 2026-05-09
Score: 5.3 Medium
EPSS: 8.5% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The flaw resides in the change_wifi_password handler of the adm.cgi script on the Wavlink NU516U1 router. By supplying crafted values for the wl_channel, wl_Pass, or EncrypType parameters, an attacker can cause the backend to invoke arbitrary operating‑system commands. Successful exploitation would give the attacker full control over the device, with the ability to modify firmware or network configuration, thereby compromising confidentiality, integrity, and availability of the device and any networks it serves.

Affected Systems

The vulnerability affects all Wavlink NU516U1 routers running firmware build M16U1_V240425. The flaw is tied to that specific firmware version; any device deploying this build is susceptible, regardless of additional build numbers.

Risk and Exploitability

The base CVSS score of 5.3 reflects moderate system impact under typical privilege conditions, yet the injection allows remote code execution, elevating the risk considerably. The EPSS score of 9% indicates a moderate likelihood of exploitation in the wild, but the vulnerability is not currently listed in the CISA KEV catalogue. Attackers can trigger the flaw remotely through the web interface; while the official documentation does not explicitly state that authentication is required, the administrative CGI path suggests that privileged access is usually needed, though the possibility of unauthenticated exploitation cannot be ruled out without further evidence.

Generated by OpenCVE AI on September 26, 2026 at 07:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Wavlink that removes the command‑injection flaw on the NU516U1 router.
  • Restrict external access to the /cgi‑bin/adm.cgi interface, for example by placing the router behind a firewall or limiting the IP range that can reach it.
  • If a firmware update is unavailable, disable or lock the Wi‑Fi password change capability, enforce strict authentication for any Wi‑Fi configuration changes, and ensure that all input handling is properly validated to prevent command injection.

Generated by OpenCVE AI on September 26, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink wl-nu516u1 Firmware
CPEs cpe:2.3:h:wavlink:wl-nu516u1:-:*:*:*:*:*:*:*
cpe:2.3:o:wavlink:wl-nu516u1_firmware:m16u1_v240425:*:*:*:*:*:*:*
Vendors & Products Wavlink wl-nu516u1 Firmware

Mon, 11 May 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 10 May 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink
Wavlink wl-nu516u1
Vendors & Products Wavlink
Wavlink wl-nu516u1

Sat, 09 May 2026 15:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the file /cgi-bin/adm.cgi. The manipulation of the argument wl_channel/wl_Pass/EncrypType leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.
Title Wavlink NU516U1 adm.cgi change_wifi_password os command injection
Weaknesses CWE-77
CWE-78
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wavlink Wl-nu516u1 Wl-nu516u1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-11T17:32:10.946Z

Reserved: 2026-05-08T19:52:02.937Z

Link: CVE-2026-8188

cve-icon Vulnrichment

Updated: 2026-05-11T16:03:54.673Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-09T16:16:08.870

Modified: 2026-07-24T08:10:00.150

Link: CVE-2026-8188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T07:30:09Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')