Executive brief
A vulnerability exists in the Wavlink NU516U1 USB Network Printer Server, a device used to share printers across a local network. An attacker can exploit this flaw to take complete control of the device by executing unauthorized system commands. This could lead to the interception of print jobs, unauthorized access to the local network, or the use of the device as a foothold for further attacks.
Technical details
An OS command injection vulnerability exists in the Wavlink NU516U1 USB Network Printer Server running firmware version M16U1_V240425. The flaw is located within the 'wzdrepeater' function of the '/cgi-bin/adm.cgi' component. Specifically, the application fails to properly sanitize the 'wlan_bssid', 'sel_Automode', and 'sel_EncrypTyp' parameters before passing them to a system shell. A remote attacker with low privileges can exploit this by sending a crafted HTTP POST request containing shell metacharacters (e.g., using $() syntax) to execute arbitrary OS commands with the privileges of the web server. A public proof-of-concept demonstrates achieving a remote shell via telnetd.
Affected products
- Wavlink NU516U1 (WL-NU516U1) M16U1_V240425
Timeline
- 2026-05-09: disclosed: Initial disclosure and VulDB entry creation
- 2026-05-09: advisory: CVE-2026-8189 published