Executive brief
A security vulnerability has been identified in the Wavlink WL-NU516U1 router, a device used to provide wireless internet connectivity. An attacker could exploit this flaw to take control of the router's operating system, potentially leading to unauthorized access to network traffic or a complete service outage. A fixed version of the firmware has been released by the manufacturer to address this issue.
Technical details
An OS command injection vulnerability exists in the Wavlink WL-NU516U1 router firmware version 260515. The flaw is located within the 'wlink_uci_set_value' function in '/cgi-bin/adm.cgi' due to improper neutralization of the 'lan_ip' argument before it is passed to a system call. A remote attacker with low privileges can exploit this by sending a specially crafted request to execute arbitrary commands on the underlying Linux operating system. Public exploit code exists, and the vulnerability can reportedly be chained with CSRF to bypass authentication. A firmware update (WINSTAR_NU516U1-WO-A-2026-06-22) is available to remediate the issue.
Affected products
- Wavlink WL-NU516U1 260515
Timeline
- 2026-07-13: advisory: NVD publication date
- 2026-06-22: patched: Vendor released fixed firmware version
References
- https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-06-22-5ccde97-mt7628-squashfs-sysupgrade.bin
- https://github.com/0xcc12138/wavlink-nu516u1-csrf-command-injection-
- https://vuldb.com/cve/CVE-2026-15513
- https://vuldb.com/submit/847517
- https://vuldb.com/vuln/377842
- https://vuldb.com/vuln/377842/cti