A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipulation of the argument ppp_username/ppp_passwd/rwan_ip/rwan_mask/rwan_gateway is directly passed by the attacker/so we can control the ppp_username/ppp_passwd/rwan_ip/rwan_mask/rwan_gateway causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
References
| Link | Resource |
|---|---|
| https://github.com/wudipjq/my_vuln/blob/main/Wavlink/vuln_3/3.md | Exploit Third Party Advisory |
| https://vuldb.com/submit/800729 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/362342 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/362342/cti | Permissions Required VDB Entry |
Configurations
Configuration 1 (hide)
| AND |
|
History
13 May 2026, 16:10
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:wavlink:wl-nu516u1:-:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wl-nu516u1_firmware:m16u1_v240425:*:*:*:*:*:*:* |
|
| References | () https://github.com/wudipjq/my_vuln/blob/main/Wavlink/vuln_3/3.md - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/submit/800729 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/362342 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/362342/cti - Permissions Required, VDB Entry | |
| First Time |
Wavlink
Wavlink wl-nu516u1 Wavlink wl-nu516u1 Firmware |
09 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-09 18:16
Updated : 2026-05-13 16:10
NVD link : CVE-2026-8190
Mitre link : CVE-2026-8190
CVE.ORG link : CVE-2026-8190
JSON object : View
Products Affected
wavlink
- wl-nu516u1_firmware
- wl-nu516u1
