PT-2026-23624 · Wavlink · Wavlink Wl-Nu516U1

Haimianbaobao

+1

·

Published

2026-03-06

·

Updated

2026-03-11

·

CVE-2026-3612

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Wavlink WL-NU516U1 version V240425
Description A command injection issue exists in the OTA Online Upgrade component of the Wavlink WL-NU516U1 V240425. The issue is located in the sub 405AF4 function of the /cgi-bin/adm.cgi file. Manipulation of the firmware url argument can lead to command injection. This allows for remote exploitation. The exploit has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-3612

Affected Products

Wavlink Wl-Nu516U1