


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/adm.cgi of the component OTA Online Upgrā¦
Published:
5 maart 2026 om 23:00:00
Alert date:
6 maart 2026 om 02:01:01
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A command injection vulnerability was discovered in Wavlink WL-NU516U1 V240425 router firmware. The vulnerability affects the OTA Online Upgrade component, specifically the sub_405AF4 function in /cgi-bin/adm.cgi. Attackers can manipulate the firmware_url argument to achieve command injection. The attack can be initiated remotely and the exploit has been publicly disclosed. The vendor was contacted about this disclosure.
Technical details
Mitigation steps:
Affected products:
Wavlink WL-NU516U1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-3612
https://github.com/Wlz1112/WAVLINK-NU516-V240425/blob/main/firmware_url.md
https://vuldb.com/?ctiid.349220
https://vuldb.com/?id.349220
https://vuldb.com/?submit.754668
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
