PT-2026-53208 · Wavlink · Wl-Nu516U1-A
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Wavlink WL-NU516U1-A version M16U1 V240425
Description
Command injection is possible via the POST Parameter Handler in the
/cgi-bin/wireless.cgi endpoint. The issue exists within the sub 401D68() function and is triggered by the manipulation of the SSID2G2, SSID5G2, AuthMethod2, or WPAPSK12 arguments. This allows for remote exploitation.Recommendations
Upgrade Wavlink WL-NU516U1-A version M16U1 V240425 to the fixed version released by the vendor.
Exploit
Fix
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wl-Nu516U1-A