PT-2026-20333 · Wavlink · Wavlink Wl-Nu516U1

Haimianbaobao

·

Published

2026-02-17

·

Updated

2026-02-22

·

CVE-2026-2615

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Wavlink WL-NU516U1 versions up to 20251208
Description A flaw exists in Wavlink WL-NU516U1 that could allow for remote command injection. The issue is located in the singlePortForwardDelete function within the /cgi-bin/firewall.cgi file. Manipulation of the del flag argument can trigger the issue. The exploit has been published.
Recommendations Versions up to 20251208 should be updated when a fix becomes available. As a temporary workaround, consider restricting access to the /cgi-bin/firewall.cgi file.

Exploit

Fix

Command Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2615

Affected Products

Wavlink Wl-Nu516U1