Junglewise Threat Intelligence

CVE-2026-8192: Wavlink NU516U1 OS command injection in adm.cgi

CVE-2026-8192 · Severity: medium · CVSS 6.3 · Published 2026-05-09

Technologies: Wavlink Wl-Nu516u1 Firmware, Wavlink Wl-Nu516u1, Wavlink NU516U1. Vendors: Wavlink.

Executive brief

A security vulnerability exists in the Wavlink NU516U1 USB Network Printer Server, a device used to share printers across a network. An attacker can exploit this flaw to take complete control of the device by executing unauthorized system commands. This could lead to the device being used as a foothold for further attacks on the local network or a total loss of device functionality.

Technical details

An OS command injection vulnerability exists in the 'wzdap' function within the '/cgi-bin/adm.cgi' file of Wavlink NU516U1 firmware version M16U1_V240425. The root cause is the improper neutralization of special elements in the 'EncrypType' and 'wl_Pass' HTTP POST parameters, which are passed directly to a system shell. A remote attacker with low-privileged access can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary commands, such as starting a telnet daemon for remote shell access. While the vendor was contacted, no official patch was confirmed at the time of disclosure, and a public proof-of-concept is available.

Affected products

  • Wavlink NU516U1 M16U1_V240425

Timeline

  • 2026-05-09: disclosed: Initial disclosure and public exploit release
  • 2026-05-09: advisory

References

Related threats