Command Injection Vulnerability in Wavlink NU516U1 Wireless Configuration
CVE-2025-10961
What is CVE-2025-10961?
A command injection vulnerability has been identified in the Wavlink NU516U1 device, specifically within the Delete_Mac_list functionality of the wireless.cgi script. This vulnerability arises from insufficient input validation in the function sub_4030C0. An attacker can exploit this flaw by crafting a malicious delete_list argument, allowing them to execute arbitrary commands on the device. Despite early notification of this vulnerability to the vendor, there has been no response, highlighting the importance of addressing vulnerabilities promptly to maintain device and network security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
NU516U1 M16U1_V240425
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
