Junglewise Threat Intelligence

CVE-2026-8191: Wavlink NU516U1 command injection in adm.cgi

CVE-2026-8191 · Severity: medium · CVSS 6.3 · Published 2026-05-09

Technologies: Wavlink Wl-Nu516u1 Firmware, Wavlink Wl-Nu516u1, Wavlink NU516U1. Vendors: Wavlink.

Executive brief

A vulnerability exists in the Wavlink NU516U1 USB Network Printer Server, a device used to share printers across a network. An attacker can exploit this flaw to take complete control of the device by executing unauthorized system commands. This could lead to the device being used as a foothold for further attacks on the internal network or a total loss of the device's functionality.

Technical details

An OS command injection vulnerability exists in the Wavlink NU516U1 USB Network Printer Server (firmware version M16U1_V240425). The flaw is located within the 'wifi_region' function in the '/cgi-bin/adm.cgi' component. The application fails to properly sanitize the 'skiplist1' and 'skiplist2' arguments before passing them to a system shell. A remote attacker with low-level authenticated access can exploit this by sending a specially crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary commands with the privileges of the web server. A public Proof-of-Concept (PoC) demonstrating the ability to start a telnet daemon for remote shell access is available.

Affected products

  • Wavlink NU516U1 USB Network Printer Server M16U1_V240425

Timeline

  • 2026-05-09: disclosed: Initial disclosure and VulDB entry creation
  • 2026-05-09: advisory: NVD publication date

References

Related threats