Impact
A flaw in the advance function of /cgi-bin/wireless.cgi on the Wavlink NU516U1 router allows an attacker to manipulate the wlan_conf/Channel/skiplist/ieee_80211h argument and inject arbitrary shell commands. The injected commands are executed with the privileges of the router’s operating system, giving the attacker the capability to alter firmware settings, read confidential data, or pivot to other devices on the network. This is a classic operating‑system command injection vulnerability (CWE‑77/78).
Affected Systems
The vulnerability affects the Wavlink NU516U1 model running firmware release 240425. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring network access to the router’s web interface. No evidence of active exploitation is reported, but the publicly disclosed exploit demonstrates the feasibility of remote command execution on this device.
OpenCVE Enrichment