PT-2025-39442 · Wavlink · Wavlink Nu516U1

Panda_0X1

·

Published

2025-09-11

·

Updated

2025-09-26

·

CVE-2025-10964

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wavlink NU516U1 (affected versions not specified)
Description A flaw exists in the Wavlink NU516U1 device. The issue is related to the manipulation of the remoteManagementEnabled argument within the sub 401B30 function of the /cgi-bin/firewall.cgi file, leading to command injection. This allows for remote exploitation. The exploit is publicly available. The vendor was notified but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-16410
CVE-2025-10964

Affected Products

Wavlink Nu516U1