top of page
perceptive_background_267k.jpg

A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation…

Published:

2 augustus 2026 om 22:00:00

Alert date:

3 augustus 2026 om 08:02:36

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure

A vulnerability identified as CVE-2026-18587 has been discovered in the Wavlink WL-NU516U1 device running firmware version 708c073-mt7628. The flaw resides in an unknown function within the Config Import component, where manipulation of the Password argument can lead to OS command injection. The attack can be launched remotely, though it is characterized by high complexity and is considered difficult to exploit. The exploit has been publicly disclosed and could be weaponized. The vendor was notified early, responded professionally, and has released a patched firmware version. Users are advised to upgrade to the fixed firmware version to mitigate the risk. The vulnerability has been documented on NVD, VulDB, and a GitHub proof-of-concept report has been published.

Technical details

Mitigation steps:

Affected products:

Wavlink WL-NU516U1 708c073-mt7628

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page