CVE-2026-18587 Details
Description
A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of the argument Password can lead to os command injection. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is regarded as difficult. The exploit has been published and may be used. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A command injection vulnerability has been identified in the Wavlink WL-NU516U1 router, specifically in the Config Import feature. This flaw allows remote execution of operating system commands by manipulating the Password argument. The vulnerability is characterized by high complexity, making exploitation difficult.
Users are advised to upgrade to the latest version of the firmware, which includes a fix for this vulnerability. The updated firmware can be downloaded from the Wavlink Firmware Download Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 3, 2026CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/submit/850494 | CISA-ADP | Issue TrackingPermission Required |
| https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-07-13-4b8a21f-mt7628-squashfs-sysupgrade.bin | [email protected] | Broken LinkVendor |
| https://github.com/oduoke567/WAVLINK-NU516U1-2026-05-1/blob/main/report.md | [email protected] | Broken LinkTechnical Description |
| https://vuldb.com/cve/CVE-2026-18587 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/850494 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/385415 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/385415/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Wavlink WL-NU516U1 | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | [email protected] |
Volerion