PT-2025-39432 · Wavlink · Wavlink Nu516U1+1

Panda_0X1

·

Published

2025-09-11

·

Updated

2026-03-08

·

CVE-2025-10959

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wavlink NU516U1 M16U1 V240425
Description A flaw exists that allows for remote command injection. The issue is located in the sub 401778 function within the /cgi-bin/firewall.cgi file. Manipulation of the dmz flag argument can trigger the flaw. The exploit has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

BDU:2025-16413
CVE-2025-10959

Affected Products

M16U1 V240425
Wavlink Nu516U1