Impact
The vulnerability is an OS command injection flaw in the wzdrepeater function of the /cgi-bin/adm.cgi script on Wavlink NU516U1 routers. By manipulating the wlan_bssid/sel_Automode/sel_EncrypTyp parameters, an attacker can inject arbitrary shell commands, enabling remote execution of any command on the device. This weakness is characterized by CWE‑77 and CWE‑78 and could compromise the router’s integrity, confidentiality, and network connectivity.
Affected Systems
The affected product is the Wavlink NU516U1 router running firmware build M16U1_V240425. No other models or firmware versions are explicitly indicated in the advisory, so the scope appears limited to this firmware configuration.
Risk and Exploitability
The CVSS score of 5.3 suggests moderate severity, and the EPSS score of 5% indicates a low probability of exploitation based on historical data, though the vulnerability has been publicly disclosed. Based on the description, it is inferred that the attack vector is remote – a network attacker with access to the router’s administrative web interface can trigger the injection by sending crafted HTTP requests. The lack of a KEV listing means no publicly confirmed exploitation is currently documented, but the public availability of exploits warrants caution.
OpenCVE Enrichment