Junglewise Threat Intelligence

CVE-2026-8190: Wavlink NU516U1 OS command injection in adm.cgi

CVE-2026-8190 · Severity: medium · CVSS 6.3 · Published 2026-05-09

Technologies: Wavlink Wl-Nu516u1 Firmware, Wavlink Wl-Nu516u1, Wavlink NU516U1 firmware. Vendors: Wavlink.

Executive brief

A vulnerability exists in the Wavlink NU516U1 USB Network Printer Server, a device used to share printers across a network. An attacker can exploit this flaw to take complete control of the device, potentially leading to unauthorized access to network traffic or using the device as a foothold for further attacks. This could result in a total loss of confidentiality and service availability for the affected hardware.

Technical details

An OS command injection vulnerability exists in the 'wan' function of the /cgi-bin/adm.cgi component in Wavlink NU516U1 firmware version M16U1_V240425. The issue stems from improper neutralization of special elements in several parameters, including ppp_username, ppp_passwd, rwan_ip, rwan_mask, and rwan_gateway. A remote attacker with low privileges can exploit this by sending a crafted POST request containing shell metacharacters (e.g., using $() syntax) to execute arbitrary commands on the underlying operating system. A public proof-of-concept demonstrates achieving a remote shell via telnetd. While the vendor was contacted, no official patch has been confirmed in the advisory.

Affected products

  • Wavlink NU516U1 Firmware M16U1_V240425

Timeline

  • 2026-05-09: disclosed: Vulnerability disclosed via VulDB and GitHub PoC
  • 2026-05-09: advisory

References

Related threats