ZeroHour

CVE-2025-10775

PoC niche

OS Command Injection in Wavlink WL-NU516U1 login.cgi

CVSS 4.0
2.0 low
EPSS
20%p97
Published
()
Modified
AI analysis

Wavlink WL-NU516U1 firmware (build 240425) contains an OS command injection flaw in the sub_4012A0 function of /cgi-bin/login.cgi, where the ipaddr argument is passed to a command interpreter without proper sanitization. A remote attacker triggers the flaw by submitting a crafted ipaddr value to the login.cgi endpoint, causing arbitrary operating-system commands to run on the device. Successful exploitation yields command execution on the router, though the CVSS 4.0 vector (PR:H, low confidentiality/integrity/availability impact) indicates the attack requires high privileges and has a limited footprint on the affected system. Owners and operators running the disclosed WL-NU516U1 firmware, particularly those whose web administration interface is reachable from the internet, are affected. A public proof-of-concept is available, the issue is not yet in CISA's KEV catalog, EPSS estimates a roughly 20% chance of exploitation within 30 days, and the vendor was notified but has not responded.

What to do: Inventory networks for Wavlink WL-NU516U1 routers and check the running firmware build (240425 was named in the disclosure). Because the vendor has not responded to the disclosure and no patched version is confirmed, do not expose the device's web administration interface (and specifically /cgi-bin/login.cgi) to the internet; restrict access to trusted management networks or via firewall/ACL rules. Review HTTP logs for requests to /cgi-bin/login.cgi containing shell metacharacters in the ipaddr parameter as an indicator of probing or exploitation.

Affected
Wavlink WL-NU516U1 firmware240425 (the build named in the disclosure; no broader version range was provided)
Estimated exposure
nichelikely hundreds to low thousands of internet-exposed units (single niche consumer model) — Public internet scans show only on the order of tens of thousands of Wavlink devices exposed across all models, and this single budget-consumer router model plausibly represents only a small fraction of that fleet, so the affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_4012A0 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Vendors
wavlink
Products
wl-nu516u1 firmware
Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.