PT-2026-57579 · Wavlink · Wl-Nu516U1

·

CVE-2026-15513

·

Published

2026-07-12

·

Updated

2026-07-13

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Wavlink WL-NU516U1 version 260515
Description A flaw in the /cgi-bin/adm.cgi endpoint allows remote OS command injection. The issue occurs when the lan ip argument is manipulated, as the value is stored unfiltered and subsequently executed via a second request. This stored injection is further facilitated by weak Cross-Site Request Forgery (CSRF) and Referer checks, potentially allowing attacks to be launched from malicious websites. Exploitation can lead to DNS hijacking, Man-in-the-Middle (MITM) attacks, and lateral movement within the local area network. The vulnerability specifically affects the wlink uci set value() function.
Recommendations Update Wavlink WL-NU516U1 version 260515 to the fixed firmware version released by the vendor.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15513

Affected Products

Wl-Nu516U1