OS Command Injection Vulnerability in Wavlink WL-NU516U1 Router
CVE-2026-18590
5.3MEDIUM
What is CVE-2026-18590?
A security vulnerability in the Wavlink WL-NU516U1 router's admin interface allows for OS command injection through improper handling of user input in the set_sys_adm function located in the adm.cgi file. This issue can be exploited remotely, posing significant threats to device security. Following public disclosure, Wavlink swiftly addressed the problem and released an updated version of the firmware to remediate the vulnerability. Users are strongly advised to upgrade their devices to prevent potential exploits.
Affected Version(s)
WL-NU516U1 708c073-mt7628
