Junglewise Threat Intelligence

CVE-2026-8188: Wavlink NU516U1 command injection in change_wifi_password

CVE-2026-8188 · Severity: medium · CVSS 6.3 · Published 2026-05-09

Technologies: Wavlink Wl-Nu516u1 Firmware, Wavlink Wl-Nu516u1, Wavlink NU516U1 firmware, Wavlink NU516U1. Vendors: Wavlink.

Executive brief

A vulnerability exists in the Wavlink NU516U1 USB Network Printer Server, a device used to share printers across a network. An attacker can exploit this flaw to take complete control of the device by executing unauthorized system commands. This could lead to the interception of print jobs, unauthorized access to the local network, or the use of the device as a foothold for further attacks.

Technical details

An OS command injection vulnerability exists in the 'change_wifi_password' function within the '/cgi-bin/adm.cgi' component of Wavlink NU516U1 firmware version M16U1_V240425. The root cause is the improper neutralization of special elements in the 'wl_channel', 'wl_Pass', and 'EncrypType' parameters, which are passed directly to system shells. A remote attacker with low privileges (authenticated access to the web interface) can submit a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary commands as the root user. A public proof-of-concept demonstrates using this flaw to start a telnet daemon for remote shell access.

Affected products

  • Wavlink NU516U1 M16U1_V240425

Timeline

  • 2026-05-09: disclosed: Vulnerability disclosed to the public
  • 2026-05-09: advisory: Initial advisory published by VulDB

References

Related threats