PT-2026-23624 · Wavlink · Wavlink Wl-Nu516U1
Haimianbaobao
+1
·
Publicado
2026-03-06
·
Atualizado
2026-03-11
·
CVE-2026-3612
CVSS v2.0
8.3
Alta
| Vetor | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Wavlink WL-NU516U1 version V240425
Description
A command injection issue exists in the OTA Online Upgrade component of the Wavlink WL-NU516U1 V240425. The issue is located in the
sub 405AF4 function of the /cgi-bin/adm.cgi file. Manipulation of the firmware url argument can lead to command injection. This allows for remote exploitation. The exploit has been publicly disclosed.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Command Injection
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Wavlink Wl-Nu516U1