CVE-2025-10775
PoC nicheOS Command Injection in Wavlink WL-NU516U1 login.cgi
Wavlink WL-NU516U1 firmware (build 240425) contains an OS command injection flaw in the sub_4012A0 function of /cgi-bin/login.cgi, where the ipaddr argument is passed to a command interpreter without proper sanitization. A remote attacker triggers the flaw by submitting a crafted ipaddr value to the login.cgi endpoint, causing arbitrary operating-system commands to run on the device. Successful exploitation yields command execution on the router, though the CVSS 4.0 vector (PR:H, low confidentiality/integrity/availability impact) indicates the attack requires high privileges and has a limited footprint on the affected system. Owners and operators running the disclosed WL-NU516U1 firmware, particularly those whose web administration interface is reachable from the internet, are affected. A public proof-of-concept is available, the issue is not yet in CISA's KEV catalog, EPSS estimates a roughly 20% chance of exploitation within 30 days, and the vendor was notified but has not responded.
What to do: Inventory networks for Wavlink WL-NU516U1 routers and check the running firmware build (240425 was named in the disclosure). Because the vendor has not responded to the disclosure and no patched version is confirmed, do not expose the device's web administration interface (and specifically /cgi-bin/login.cgi) to the internet; restrict access to trusted management networks or via firewall/ACL rules. Review HTTP logs for requests to /cgi-bin/login.cgi containing shell metacharacters in the ipaddr parameter as an indicator of probing or exploitation.
| Wavlink WL-NU516U1 firmware | 240425 (the build named in the disclosure; no broader version range was provided) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_4012A0 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- wavlink
- Products
- wl-nu516u1 firmware
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.