PT-2026-23624 · Wavlink · Wavlink Wl-Nu516U1
Haimianbaobao
+1
·
Published
2026-03-06
·
Updated
2026-03-11
·
CVE-2026-3612
CVSS v2.0
8.3
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Wavlink WL-NU516U1 version V240425
Description
A command injection issue exists in the OTA Online Upgrade component of the Wavlink WL-NU516U1 V240425. The issue is located in the
sub 405AF4 function of the /cgi-bin/adm.cgi file. Manipulation of the firmware url argument can lead to command injection. This allows for remote exploitation. The exploit has been publicly disclosed.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wavlink Wl-Nu516U1