Command Injection Vulnerability in Wavlink NU516U1 Products
CVE-2025-10960
Key Information:
Badges
What is CVE-2025-10960?
A command injection vulnerability exists in the Wavlink NU516U1 product line. The flaw is located in the DeleteMac Page, specifically in the function sub_402D1C of the wireless.cgi file. By manipulating the delete_list argument, an attacker may execute arbitrary commands on the affected system. This vulnerability is accessible remotely, making it a significant risk for users. Despite being alerted about the issue, the vendor has not responded, raising concerns about the urgency of remediation.
Affected Version(s)
NU516U1 M16U1_V240425
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved