OS Command Injection Vulnerability in Wavlink WL-NU516U1 Router
CVE-2026-18590

5.3MEDIUM

Key Information:

Vendor

Wavlink

Vendor
CVE Published:
3 August 2026

What is CVE-2026-18590?

A security vulnerability in the Wavlink WL-NU516U1 router's admin interface allows for OS command injection through improper handling of user input in the set_sys_adm function located in the adm.cgi file. This issue can be exploited remotely, posing significant threats to device security. Following public disclosure, Wavlink swiftly addressed the problem and released an updated version of the firmware to remediate the vulnerability. Users are strongly advised to upgrade their devices to prevent potential exploits.

Affected Version(s)

WL-NU516U1 708c073-mt7628

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

oduoke (VulDB User)
VulDB CNA Team
.