Impact
The vulnerability is located in the wan function of the adm.cgi CGI script on Wavlink NU516U1 routers. Malicious values supplied for the ppp_username, ppp_passwd, rwan_ip, rwan_mask, or rwan_gateway parameters are concatenated into operating‑system commands without proper sanitization, allowing an attacker to inject arbitrary commands and execute them with the web interface process’s privileges.
Affected Systems
Wavlink NU516U1 devices running firmware version M16U1_V240425 are affected; no other vendors, products, or versions are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate overall risk. An EPSS score of 9% suggests a non‑negligible probability of exploitation, though the vulnerability is not currently listed in the CISA KEV catalog. The flaw can be triggered remotely by sending a crafted HTTP request to the router’s administrative interface, and it has been publicly disclosed.
OpenCVE Enrichment