Impact
The flaw resides in the change_wifi_password handler of the adm.cgi script on the Wavlink NU516U1 router. By supplying crafted values for the wl_channel, wl_Pass, or EncrypType parameters, an attacker can cause the backend to invoke arbitrary operating‑system commands. Successful exploitation would give the attacker full control over the device, with the ability to modify firmware or network configuration, thereby compromising confidentiality, integrity, and availability of the device and any networks it serves.
Affected Systems
The vulnerability affects all Wavlink NU516U1 routers running firmware build M16U1_V240425. The flaw is tied to that specific firmware version; any device deploying this build is susceptible, regardless of additional build numbers.
Risk and Exploitability
The base CVSS score of 5.3 reflects moderate system impact under typical privilege conditions, yet the injection allows remote code execution, elevating the risk considerably. The EPSS score of 9% indicates a moderate likelihood of exploitation in the wild, but the vulnerability is not currently listed in the CISA KEV catalogue. Attackers can trigger the flaw remotely through the web interface; while the official documentation does not explicitly state that authentication is required, the administrative CGI path suggests that privileged access is usually needed, though the possibility of unauthenticated exploitation cannot be ruled out without further evidence.
OpenCVE Enrichment