A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-bin/adm.cgi. Such manipulation of the argument skiplist1/skiplist2 leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
References
| Link | Resource |
|---|---|
| https://github.com/wudipjq/my_vuln/blob/main/Wavlink/vuln_4/4.md | Exploit Third Party Advisory |
| https://vuldb.com/submit/800730 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/362343 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/362343/cti | Permissions Required VDB Entry |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-05-09 19:16
Updated : 2026-07-24 08:10
NVD link : CVE-2026-8191
Mitre link : CVE-2026-8191
CVE.ORG link : CVE-2026-8191
JSON object : View
Products Affected
wavlink
- wl-nu516u1
- wl-nu516u1_firmware
