PT-2026-39401 · Wavlink · Nu516U1

Ziyue Xie

·

Published

2026-05-09

·

Updated

2026-05-09

·

CVE-2026-8190

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A vulnerability was determined in Wavlink NU516U1 M16U1 V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipulation of the argument ppp username/ppp passwd/rwan ip/rwan mask/rwan gateway is directly passed by the attacker/so we can control the ppp username/ppp passwd/rwan ip/rwan mask/rwan gateway causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.

Exploit

Fix

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-8190

Affected Products

Nu516U1