CVE-2026-8189: Wavlink NU516U1 adm.cgi wzdrepeater os command injection
A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. The manipulation of the argument wlan_bssid/sel_Automode/sel_EncrypTyp results in os command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8189?
CVE-2026-8189 has a critical severity level due to its potential for remote code execution through OS command injection.
How can I mitigate CVE-2026-8189?
To mitigate CVE-2026-8189, update the Wavlink NU516U1 firmware to the latest available version that addresses this vulnerability.
What is the impact of CVE-2026-8189?
The impact of CVE-2026-8189 allows attackers to execute arbitrary OS commands, potentially leading to full system compromise.
Which devices are affected by CVE-2026-8189?
The vulnerability CVE-2026-8189 affects the Wavlink NU516U1 device running the M16U1_V240425 firmware version.
What specific function is exploited in CVE-2026-8189?
CVE-2026-8189 exploits the wzdrepeater function within the adm.cgi file for command injection.