Wavlink · Wl-Nu516U1-A · CVE-2026-13538
**Name of the Vulnerable Software and Affected Versions**
Wavlink WL-NU516U1-A version M16U1 V240425
**Description**
Command injection is possible via the POST Parameter Handler in the `/cgi-bin/wireless.cgi` endpoint. The issue exists within the `sub 401D68()` function and is triggered by the manipulation of the `SSID2G2`, `SSID5G2`, `AuthMethod2`, or `WPAPSK12` arguments. This allows for remote exploitation.
**Recommendations**
Upgrade Wavlink WL-NU516U1-A version M16U1 V240425 to the fixed version released by the vendor.