Description
A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. The manipulation of the argument wlan_bssid/sel_Automode/sel_EncrypTyp results in os command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.
Published: 2026-05-09
Score: 5.3 Medium
EPSS: 4.8% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an OS command injection flaw in the wzdrepeater function of the /cgi-bin/adm.cgi script on Wavlink NU516U1 routers. By manipulating the wlan_bssid/sel_Automode/sel_EncrypTyp parameters, an attacker can inject arbitrary shell commands, enabling remote execution of any command on the device. This weakness is characterized by CWE‑77 and CWE‑78 and could compromise the router’s integrity, confidentiality, and network connectivity.

Affected Systems

The affected product is the Wavlink NU516U1 router running firmware build M16U1_V240425. No other models or firmware versions are explicitly indicated in the advisory, so the scope appears limited to this firmware configuration.

Risk and Exploitability

The CVSS score of 5.3 suggests moderate severity, and the EPSS score of 5% indicates a low probability of exploitation based on historical data, though the vulnerability has been publicly disclosed. Based on the description, it is inferred that the attack vector is remote – a network attacker with access to the router’s administrative web interface can trigger the injection by sending crafted HTTP requests. The lack of a KEV listing means no publicly confirmed exploitation is currently documented, but the public availability of exploits warrants caution.

Generated by OpenCVE AI on June 18, 2026 at 13:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied firmware update that fixes the command injection in wzdrepeater.
  • If an update is not yet available, restrict remote access to the router’s web interface to trusted internal networks or disable remote administration entirely.
  • Monitor the device’s access logs for anomalous requests to /cgi-bin/adm.cgi and investigate any suspicious activity.

Generated by OpenCVE AI on June 18, 2026 at 13:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink wl-nu516u1 Firmware
CPEs cpe:2.3:h:wavlink:wl-nu516u1:-:*:*:*:*:*:*:*
cpe:2.3:o:wavlink:wl-nu516u1_firmware:m16u1_v240425:*:*:*:*:*:*:*
Vendors & Products Wavlink wl-nu516u1 Firmware

Mon, 11 May 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 10 May 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink
Wavlink wl-nu516u1
Vendors & Products Wavlink
Wavlink wl-nu516u1

Sat, 09 May 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. The manipulation of the argument wlan_bssid/sel_Automode/sel_EncrypTyp results in os command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.
Title Wavlink NU516U1 adm.cgi wzdrepeater os command injection
Weaknesses CWE-77
CWE-78
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wavlink Wl-nu516u1 Wl-nu516u1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-11T14:49:18.710Z

Reserved: 2026-05-08T19:52:05.783Z

Link: CVE-2026-8189

cve-icon Vulnrichment

Updated: 2026-05-11T14:49:15.296Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-09T17:16:08.333

Modified: 2026-06-17T11:03:36.023

Link: CVE-2026-8189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T13:15:15Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')