Description
A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/ieee_80211h leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.
Published: 2026-05-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the advance function of /cgi-bin/wireless.cgi on the Wavlink NU516U1 router allows an attacker to manipulate the wlan_conf/Channel/skiplist/ieee_80211h argument and inject arbitrary shell commands. The injected commands are executed with the privileges of the router’s operating system, giving the attacker the capability to alter firmware settings, read confidential data, or pivot to other devices on the network. This is a classic operating‑system command injection vulnerability (CWE‑77/78).

Affected Systems

The vulnerability affects the Wavlink NU516U1 model running firmware release 240425. No other vendors or product versions are listed as impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring network access to the router’s web interface. No evidence of active exploitation is reported, but the publicly disclosed exploit demonstrates the feasibility of remote command execution on this device.

Generated by OpenCVE AI on May 10, 2026 at 06:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the vendor’s website or support portal for any firmware releases that address the command injection flaw and plan to deploy them as soon as possible.
  • Restrict external access to the router’s management interface by configuring firewall rules or access control lists that allow only trusted internal IP addresses, thereby limiting the exposure of the vulnerable CGI endpoint.
  • If the wireless functionality is unnecessary, disable it or block the /cgi-bin/wireless.cgi endpoint using the router’s firewall or interface‑level restrictions to remove the attack surface.

Generated by OpenCVE AI on May 10, 2026 at 06:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink wl-nu516u1 Firmware
CPEs cpe:2.3:h:wavlink:wl-nu516u1:-:*:*:*:*:*:*:*
cpe:2.3:o:wavlink:wl-nu516u1_firmware:m16u1_v240425:*:*:*:*:*:*:*
Vendors & Products Wavlink wl-nu516u1 Firmware

Tue, 12 May 2026 03:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 10 May 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink
Wavlink wl-nu516u1
Vendors & Products Wavlink
Wavlink wl-nu516u1

Sun, 10 May 2026 04:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/ieee_80211h leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.
Title Wavlink NU516U1 wireless.cgi advance os command injection
Weaknesses CWE-77
CWE-78
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wavlink Wl-nu516u1 Wl-nu516u1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-12T02:33:15.334Z

Reserved: 2026-05-09T07:54:51.721Z

Link: CVE-2026-8228

cve-icon Vulnrichment

Updated: 2026-05-12T02:33:11.496Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-10T05:16:12.573

Modified: 2026-05-13T16:10:39.620

Link: CVE-2026-8228

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-10T20:00:05Z

Weaknesses