A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipulation of the argument ppp_username/ppp_passwd/rwan_ip/rwan_mask/rwan_gateway is directly passed by the attacker/so we can control the ppp_username/ppp_passwd/rwan_ip/rwan_mask/rwan_gateway causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
References
| Link | Resource |
|---|---|
| https://github.com/wudipjq/my_vuln/blob/main/Wavlink/vuln_3/3.md | Exploit Third Party Advisory |
| https://vuldb.com/submit/800729 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/362342 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/362342/cti | Permissions Required VDB Entry |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-05-09 18:16
Updated : 2026-07-24 08:10
NVD link : CVE-2026-8190
Mitre link : CVE-2026-8190
CVE.ORG link : CVE-2026-8190
JSON object : View
Products Affected
wavlink
- wl-nu516u1
- wl-nu516u1_firmware
