A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. The manipulation of the argument wlan_bssid/sel_Automode/sel_EncrypTyp results in os command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.
Metrics
Affected Vendors & Products
References
History
Sun, 10 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wavlink
Wavlink wl-nu516u1 |
|
| Vendors & Products |
Wavlink
Wavlink wl-nu516u1 |
Sat, 09 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. The manipulation of the argument wlan_bssid/sel_Automode/sel_EncrypTyp results in os command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure. | |
| Title | Wavlink NU516U1 adm.cgi wzdrepeater os command injection | |
| Weaknesses | CWE-77 CWE-78 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-05-09T16:15:09.043Z
Updated: 2026-05-09T16:15:09.043Z
Reserved: 2026-05-08T19:52:05.783Z
Link: CVE-2026-8189
No data.
Status : Received
Published: 2026-05-09T17:16:08.333
Modified: 2026-05-09T17:16:08.333
Link: CVE-2026-8189
No data.
ReportizFlow