Impact
A remote attacker can manipulate the skiplist1 or skiplist2 query parameters of the adm.cgi wifi_region function on the Wavlink NU516U1 router, enabling OS command injection that yields arbitrary command execution on the device’s operating system. The vulnerability exploits weaknesses in command construction (CWE‑77/78) and could be triggered without local access if the web administration interface is exposed to the Internet. If authentication is required, the attacker would have to bypass or abuse it (inferred).
Affected Systems
The flaw exists in the Wavlink NU516U1 router running firmware M16U1_V240425. Any deployment that enables the adm.cgi web‑management interface, particularly over untrusted networks, is susceptible. Devices that leave remote administration enabled or lack authentication controls are believed to face higher risk (inferred).
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, while the EPSS score of 9% suggests a higher likelihood of exploitation. An exploit is publicly available, which raises the likelihood of real‑world attacks, but the vulnerability is not listed in KEV. The attack can be launched remotely by sending crafted HTTP requests to the adm.cgi interface; if authentication is required, the attacker would need to bypass or abuse it (inferred). Overall, the risk is moderate, but the higher exploitation probability heightens concern.
OpenCVE Enrichment