PT-2026-67145 · Wavlink · Wl-Nu516U1

·

CVE-2026-18587

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Wavlink WL-NU516U1 version 708c073-mt7628
Description A flaw in the Config Import component allows for remote OS command injection. This occurs when the Password argument is manipulated within an unknown function. OS command injection is a technique where an attacker executes arbitrary operating system commands on the target machine.
Recommendations Upgrade the affected component to the fixed version released by the vendor.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18587

Affected Products

Wl-Nu516U1