Executive brief
A vulnerability exists in the Wavlink NU516U1 USB Network Printer Server, a device used to share printers across a network. An attacker can exploit this flaw to take complete control of the device by executing unauthorized system commands. This could lead to the interception of print jobs, unauthorized access to the local network, or the use of the device as a foothold for further attacks.
Technical details
An OS command injection vulnerability exists in the 'change_wifi_password' function within the '/cgi-bin/adm.cgi' component of Wavlink NU516U1 firmware version M16U1_V240425. The root cause is the improper neutralization of special elements in the 'wl_channel', 'wl_Pass', and 'EncrypType' parameters, which are passed directly to system shells. A remote attacker with low privileges (authenticated access to the web interface) can submit a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary commands as the root user. A public proof-of-concept demonstrates using this flaw to start a telnet daemon for remote shell access.
Affected products
- Wavlink NU516U1 M16U1_V240425
Timeline
- 2026-05-09: disclosed: Vulnerability disclosed to the public
- 2026-05-09: advisory: Initial advisory published by VulDB