A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-bin/adm.cgi. Such manipulation of the argument skiplist1/skiplist2 leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
References
| Link | Resource |
|---|---|
| https://github.com/wudipjq/my_vuln/blob/main/Wavlink/vuln_4/4.md | Exploit Third Party Advisory |
| https://vuldb.com/submit/800730 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/362343 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/362343/cti | Permissions Required VDB Entry |
Configurations
Configuration 1 (hide)
| AND |
|
History
13 May 2026, 16:10
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:wavlink:wl-nu516u1:-:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wl-nu516u1_firmware:m16u1_v240425:*:*:*:*:*:*:* |
|
| First Time |
Wavlink
Wavlink wl-nu516u1 Wavlink wl-nu516u1 Firmware |
|
| References | () https://github.com/wudipjq/my_vuln/blob/main/Wavlink/vuln_4/4.md - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/submit/800730 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/362343 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/362343/cti - Permissions Required, VDB Entry |
09 May 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-09 19:16
Updated : 2026-05-13 16:10
NVD link : CVE-2026-8191
Mitre link : CVE-2026-8191
CVE.ORG link : CVE-2026-8191
JSON object : View
Products Affected
wavlink
- wl-nu516u1_firmware
- wl-nu516u1
