Executive brief
A security vulnerability exists in the Wavlink NU516U1 USB Network Printer Server, a device used to share printers across a network. An attacker can exploit this flaw to take complete control of the device by executing unauthorized system commands. This could lead to the device being used as a foothold for further attacks on the local network or a total loss of device functionality.
Technical details
An OS command injection vulnerability exists in the 'wzdap' function within the '/cgi-bin/adm.cgi' file of Wavlink NU516U1 firmware version M16U1_V240425. The root cause is the improper neutralization of special elements in the 'EncrypType' and 'wl_Pass' HTTP POST parameters, which are passed directly to a system shell. A remote attacker with low-privileged access can exploit this by sending a crafted POST request containing shell metacharacters (e.g., backticks) to execute arbitrary commands, such as starting a telnet daemon for remote shell access. While the vendor was contacted, no official patch was confirmed at the time of disclosure, and a public proof-of-concept is available.
Affected products
- Wavlink NU516U1 M16U1_V240425
Timeline
- 2026-05-09: disclosed: Initial disclosure and public exploit release
- 2026-05-09: advisory