Description
A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipulation of the argument ppp_username/ppp_passwd/rwan_ip/rwan_mask/rwan_gateway is directly passed by the attacker/so we can control the ppp_username/ppp_passwd/rwan_ip/rwan_mask/rwan_gateway causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
Published: 2026-05-09
Score: 5.3 Medium
EPSS: 8.5% Low
KEV: No
Impact: Remote OS Command Execution
Action: Patch
AI Analysis

Impact

The vulnerability is located in the wan function of the adm.cgi CGI script on Wavlink NU516U1 routers. Malicious values supplied for the ppp_username, ppp_passwd, rwan_ip, rwan_mask, or rwan_gateway parameters are concatenated into operating‑system commands without proper sanitization, allowing an attacker to inject arbitrary commands and execute them with the web interface process’s privileges.

Affected Systems

Wavlink NU516U1 devices running firmware version M16U1_V240425 are affected; no other vendors, products, or versions are listed.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate overall risk. An EPSS score of 9% suggests a non‑negligible probability of exploitation, though the vulnerability is not currently listed in the CISA KEV catalog. The flaw can be triggered remotely by sending a crafted HTTP request to the router’s administrative interface, and it has been publicly disclosed.

Generated by OpenCVE AI on September 26, 2026 at 07:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Wavlink firmware that contains the fix for the adm.cgi command injection flaw.
  • If an update is not immediately available, block or limit external access to the /cgi-bin/adm.cgi endpoint using firewall rules or by placing the device behind an internal network segment.
  • Enforce strong administrator credentials and, if possible, disable or remove the WAN configuration feature on devices that do not require it.

Generated by OpenCVE AI on September 26, 2026 at 07:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink wl-nu516u1 Firmware
CPEs cpe:2.3:h:wavlink:wl-nu516u1:-:*:*:*:*:*:*:*
cpe:2.3:o:wavlink:wl-nu516u1_firmware:m16u1_v240425:*:*:*:*:*:*:*
Vendors & Products Wavlink wl-nu516u1 Firmware

Mon, 11 May 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 10 May 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink
Wavlink wl-nu516u1
Vendors & Products Wavlink
Wavlink wl-nu516u1

Sat, 09 May 2026 17:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipulation of the argument ppp_username/ppp_passwd/rwan_ip/rwan_mask/rwan_gateway is directly passed by the attacker/so we can control the ppp_username/ppp_passwd/rwan_ip/rwan_mask/rwan_gateway causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
Title Wavlink NU516U1 adm.cgi wan os command injection
Weaknesses CWE-77
CWE-78
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wavlink Wl-nu516u1 Wl-nu516u1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-11T17:21:24.425Z

Reserved: 2026-05-08T19:52:08.350Z

Link: CVE-2026-8190

cve-icon Vulnrichment

Updated: 2026-05-11T17:12:33.446Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-09T18:16:22.293

Modified: 2026-07-24T08:10:00.150

Link: CVE-2026-8190

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T08:00:12Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')