What is CVE-2026-18587?
A critical vulnerability in the Config Import component of Wavlink WL-NU516U1 allows unauthenticated remote attackers to perform OS command injection via the `Password` argument. This can lead to full device compromise, so the upcoming security patch from the vendor must be applied immediately or the device's remote management features should be disabled.
Azərbaycanca: Wavlink WL-NU516U1 cihazının Config Import komponentində aşkar edilmiş bu kritik boşluq, uzaqdan autentifikasiya olunmadan `Password` arqumenti vasitəsilə OS command injection həyata keçirməyə imkan verir. Bu, cihazın tam ələ keçirilməsinə səbəb ola bilər, ona görə də istehsalçının buraxacağı təhlükəsizlik yeniləməsi dərhal tətbiq edilməli və ya cihazın uzaqdan idarəetmə funksiyaları söndürülməlidir.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: Wavlink
FAQ2
Which component of the Wavlink WL-NU516U1 device does the CVE-2026-18587 vulnerability affect?
This critical vulnerability has been identified in the Config Import component of the Wavlink WL-NU516U1 device.
How can an unauthenticated remote attack be performed using the CVE-2026-18587 vulnerability?
The vulnerability allows unauthenticated remote attackers to perform OS command injection via the `Password` argument in the Config Import component.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.