PT-2025-39438 · Wavlink · Wavlink Nu516U1 M16U1 V240425

Panda_0X1

·

Published

2025-09-11

·

Updated

2025-09-26

·

CVE-2025-10962

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wavlink NU516U1 M16U1 V240425 (affected versions not specified)
Description A flaw exists in the SetName Page component of the Wavlink NU516U1 M16U1 V240425. The issue resides within the sub 403198 function of the /cgi-bin/wireless.cgi file. Manipulation of the mac 5g argument can result in command injection, allowing for remote exploitation. The exploit is publicly available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-16417
CVE-2025-10962

Affected Products

Wavlink Nu516U1 M16U1 V240425