Junglewise Threat Intelligence

CVE-2026-15513: Wavlink WL-NU516U1 OS command injection in adm.cgi

CVE-2026-15513 · Severity: medium · CVSS 6.3 · Published 2026-07-13

Technologies: Wavlink Wl-Nu516u1. Vendors: Wavlink.

Executive brief

A security vulnerability has been identified in the Wavlink WL-NU516U1 router, a device used to provide wireless internet connectivity. An attacker could exploit this flaw to take control of the router's operating system, potentially leading to unauthorized access to network traffic or a complete service outage. A fixed version of the firmware has been released by the manufacturer to address this issue.

Technical details

An OS command injection vulnerability exists in the Wavlink WL-NU516U1 router firmware version 260515. The flaw is located within the 'wlink_uci_set_value' function in '/cgi-bin/adm.cgi' due to improper neutralization of the 'lan_ip' argument before it is passed to a system call. A remote attacker with low privileges can exploit this by sending a specially crafted request to execute arbitrary commands on the underlying Linux operating system. Public exploit code exists, and the vulnerability can reportedly be chained with CSRF to bypass authentication. A firmware update (WINSTAR_NU516U1-WO-A-2026-06-22) is available to remediate the issue.

Affected products

  • Wavlink WL-NU516U1 260515

Timeline

  • 2026-07-13: advisory: NVD publication date
  • 2026-06-22: patched: Vendor released fixed firmware version

References

Related threats