A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cgi-bin/wireless.cgi. This manipulation of the argument Guest_ssid causes command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
2025-08-19T18:15:29.730
2025-10-06T18:52:46.193
Analyzed
CVSSv3.1: 6.3 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | wavlink | wl-nu516u1_firmware | m16u1_v240425 | Yes |
| Hardware | wavlink | wl-nu516u1 | - | No |