PT-2026-53208 · Wavlink · Wl-Nu516U1-A

Hustbinary

·

Published

2026-06-29

·

Updated

2026-06-29

·

CVE-2026-13538

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
A vulnerability was determined in Wavlink WL-NU516U1-A M16U1 V240425. The affected element is the function sub 401D68 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. This manipulation of the argument SSID2G2/SSID5G2/AuthMethod2/WPAPSK12 causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Exploit

Fix

Command Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13538

Affected Products

Wl-Nu516U1-A