Vulnerabilities
203 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-8230 | A flaw has been found in Wavlink NU516U1 240425. A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure. NVD description · AI analysis pending | 2.1 | 6% | PoC |
| — | |
| CVE-2026-8188 | A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the file /cgi-bin/adm.cgi. The manipulation of the argument wl_channel/wl_Pass/EncrypType leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure. NVD description · AI analysis pending | 2.1 | 7% | PoC |
| — | |
| CVE-2026-7690 | A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. This issue affects the function set_sys_adm of the file /cgi-bin/adm.cgi. This manipulation of the argument Username causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Once again the vendors acted very professional and confirms, "that the WN570HA1 firmware version R70HA1 V1410_221110 has been removed from our website." This vulnerability only affects products that are no longer supported by the maintainer. NVD description · AI analysis pending | 2.1 | 5% | PoC |
| — | |
| CVE-2026-5004 | A vulnerability was determined in Wavlink WL-WN579X3-C 231124. A vulnerability was determined in Wavlink WL-WN579X3-C 231124. This impacts the function sub_4019FC of the file /cgi-bin/firewall.cgi of the component UPNP Handler. Executing a manipulation of the argument UpnpEnabled can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 7.4 | <1% | PoC |
| — | |
| CVE-2026-4861 | A weakness has been identified in Wavlink WL-NU516U1 260227. A weakness has been identified in Wavlink WL-NU516U1 260227. This vulnerability affects the function ftext of the file /cgi-bin/nas.cgi. This manipulation of the argument Content-Length causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 7.4 | <1% | PoC |
| — | |
| CVE-2026-4543 +1 in the same advisory: …4544 | A vulnerability was found in Wavlink WL-WN578W2 221110. A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is an unknown function of the file /cgi-bin/firewall.cgi of the component POST Request Handler. Performing a manipulation of the argument dmz_flag/del_flag results in command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 2.1 group max | 6% | PoC ×2 |
| — | |
| CVE-2026-3715 +1 in the same advisory: …3716 | A vulnerability was found in Wavlink WL-WN579X3-C 231124. A vulnerability was found in Wavlink WL-WN579X3-C 231124. This affects the function sub_40139C of the file /cgi-bin/firewall.cgi. Performing a manipulation of the argument del_flag results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 20260226 is able to mitigate this issue. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. NVD description · AI analysis pending | 7.4 group max | <1% | PoC |
| — | |
| CVE-2026-3703 +1 in the same advisory: …3704 | A flaw has been found in Wavlink NU516U1 251208. A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to out-of-bounds write. The attack may be performed from remote. The exploit has been published and may be used. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. NVD description · AI analysis pending | 8.9 group max | <1% | PoC ×2 |
| — | |
| CVE-2026-3662 +1 in the same advisory: …3661 | A vulnerability has been found in Wavlink WL-NU516U1 240425. A vulnerability has been found in Wavlink WL-NU516U1 240425. This vulnerability affects the function usb_p910 of the file /cgi-bin/adm.cgi. Such manipulation of the argument Pr_mode leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure. NVD description · AI analysis pending | 2.0 | 18% | PoC |
| — | |
| CVE-2026-3612 +1 in the same advisory: …3613 | A vulnerability was determined in Wavlink WL-NU516U1 V240425. A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/adm.cgi of the component OTA Online Upgrade. This manipulation of the argument firmware_url causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure. NVD description · AI analysis pending | 7.3 | 13% | PoC |
| — | |
| CVE-2026-2615 | A flaw has been found in Wavlink WL-NU516U1 up to 20251208. A flaw has been found in Wavlink WL-NU516U1 up to 20251208. The affected element is the function singlePortForwardDelete of the file /cgi-bin/firewall.cgi. Executing a manipulation of the argument del_flag can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 7.3 | 12% | PoC ×2 |
| — | |
| CVE-2026-2567 +1 in the same advisory: …2565 | A vulnerability was detected in Wavlink WL-NU516U1 20251208. A vulnerability was detected in Wavlink WL-NU516U1 20251208. This vulnerability affects the function sub_401218 of the file /cgi-bin/nas.cgi. Performing a manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used. NVD description · AI analysis pending | 7.3 group max | <1% | PoC |
| — | |
| CVE-2026-2529 | A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list results in command injection. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.3 group max | 8% | PoC |
| — | |
| CVE-2025-55847 | Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings.cgi file. Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings.cgi file. The vulnerability arises because the Cookie parameter does not properly validate the length of input data. Attackers can exploit this to execute arbitrary code or cause a denial of service (DoS) on the system NVD description · AI analysis pending | 8.8 | 2% | PoC |
| — | |
| CVE-2025-10961 | A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. This affects the function sub_4030C0 of the file /cgi-bin/wireless.cgi of the component Delete_Mac_list Page. Executing manipulation of the argument delete_list can lead to command injection. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.1 group max | 8% | PoC |
| — | |
| CVE-2025-10775 | OS Command Injection in Wavlink WL-NU516U1 login.cgi Wavlink WL-NU516U1 firmware (build 240425) contains an OS command injection flaw in the sub_4012A0 function of /cgi-bin/login.cgi, where the ipaddr argument is passed to a command interpreter without proper sanitization. A remote attacker triggers the flaw by submitting a crafted ipaddr value to the login.cgi endpoint, causing arbitrary operating-system commands to run on the device. Successful exploitation yields command execution on the router, though the CVSS 4.0 vector (PR:H, low confidentiality/integrity/availability impact) indicates the attack requires high privileges and has a limited footprint on the affected system. Owners and operators running the disclosed WL-NU516U1 firmware, particularly those whose web administration interface is reachable from the internet, are affected. A public proof-of-concept is available, the issue is not yet in CISA's KEV catalog, EPSS estimates a roughly 20% chance of exploitation within 30 days, and the vendor was notified but has not responded. Do: Inventory networks for Wavlink WL-NU516U1 routers and check the running firmware build (240425 was named in the disclosure). Because the vendor has not responded to the disclosure and no patched version is confirmed, do not expose the device's web administration interface (and specifically /cgi-bin/login.cgi) to the internet; restrict access to trusted management networks or via firewall/ACL rules. Review HTTP logs for requests to /cgi-bin/login.cgi containing shell metacharacters in the ipaddr parameter as an indicator of probing or exploitation. | 2.0 | 20% | PoC |
| nichelikely hundreds to low thousands of internet-exposed units (single niche consumer model) | |
| CVE-2025-10359 +1 in the same advisory: …10358 | A vulnerability was detected in Wavlink WL-WN578W2 221110. A vulnerability was detected in Wavlink WL-WN578W2 221110. This impacts the function sub_404DBC of the file /cgi-bin/wireless.cgi. The manipulation of the argument macAddr results in os command injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.5 | 6% | PoC ×2 |
| — | |
| CVE-2025-10324 | A vulnerability was determined in Wavlink WL-WN578W2 221110. A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects the function sub_401C5C of the file firewall.cgi. This manipulation of the argument pingFrmWANFilterEnabled/blockSynFloodEnabled/blockPortScanEnabled/remoteManagementEnabled causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.5 group max | 8% | PoC |
| — | |
| CVE-2025-50757 +1 in the same advisory: …50755 | Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the username parameter. Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the username parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. NVD description · AI analysis pending | 6.5 | 2% | PoC |
| — |