Description
A flaw has been found in Wavlink WL-NU516U1 240425. This affects the function ota_new_upgrade of the file /cgi-bin/adm.cgi. This manipulation of the argument model causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure.
Problem types
Product status
Timeline
| 2026-03-06: | Advisory disclosed |
| 2026-03-06: | VulDB entry created |
| 2026-03-06: | VulDB entry last update |
Credits
allanp0e (VulDB User)
VulDB
References
vuldb.com/?id.349550 (VDB-349550 | Wavlink WL-NU516U1 adm.cgi ota_new_upgrade command injection)
vuldb.com/?ctiid.349550 (VDB-349550 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.758227 (Submit #758227 | wavlink WL-NU516U1-A M16U1_V240425 Command Injection)
github.com/jinhao118/cve/blob/main/WAVLINK_1.md