CVE-2025-9149: Wavlink Wl-NU516U1 Firmware

Critical severity, CVSS 9.8. EPSS: 5.1% chance of exploitation in the next 30 days.

A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cgi-bin/wireless.cgi. This manipulation of the argument Guest_ssid causes command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

Affected products

  • Wavlink Wl-NU516U1 Firmware: version m16u1_v240425 only

Published 2025-08-19. Last modified 2026-06-17.