CVE-2026-8230: Wavlink Wl-NU516U1 Firmware

High severity, CVSS 8.8. EPSS: 8.5% chance of exploitation in the next 30 days.

A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure.

Affected products

  • Wavlink Wl-NU516U1 Firmware: version m16u1_v240425 only

Published 2026-05-10. Last modified 2026-07-24.