


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation…
Published:
2 augustus 2026 om 22:00:00
Alert date:
3 augustus 2026 om 08:02:36
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A vulnerability identified as CVE-2026-18587 has been discovered in the Wavlink WL-NU516U1 device running firmware version 708c073-mt7628. The flaw resides in an unknown function within the Config Import component, where manipulation of the Password argument can lead to OS command injection. The attack can be launched remotely, though it is characterized by high complexity and is considered difficult to exploit. The exploit has been publicly disclosed and could be weaponized. The vendor was notified early, responded professionally, and has released a patched firmware version. Users are advised to upgrade to the fixed firmware version to mitigate the risk. The vulnerability has been documented on NVD, VulDB, and a GitHub proof-of-concept report has been published.
Technical details
Mitigation steps:
Affected products:
Wavlink WL-NU516U1 708c073-mt7628
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18587
https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-07-13-4b8a21f-mt7628-squashfs-sysupgrade.bin
https://github.com/oduoke567/WAVLINK-NU516U1-2026-05-1/blob/main/report.md
https://vuldb.com/cve/CVE-2026-18587
https://vuldb.com/submit/850494
https://vuldb.com/vuln/385415
https://vuldb.com/vuln/385415/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
