Wavlink NU516U1 Command Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A command injection vulnerability has been identified in the Wavlink NU516U1 USB Network Printer Server, specifically in the M16U1_V240425 firmware. The issue arises in the 'wifi_region' function of the '/cgi-bin/adm.cgi' file, where the 'skiplist1' and 'skiplist2' arguments can be manipulated to execute arbitrary operating system commands. This vulnerability can be exploited remotely, and a proof of concept is publicly available.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device.

Reproduction

To reproduce this vulnerability, send a POST request to '/cgi-bin/adm.cgi' with the 'page' parameter set to 'wifi_region'. Include a crafted 'skiplist1' value that contains the desired command, such as 'telnetd -l /bin/sh -p 8891'. The device will execute the command, providing a shell access through the specified port.

Added: May 9, 2026, 7:18 PM
Updated: May 9, 2026, 7:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
7.8
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.