Wavlink vulnerabilities
4 CVEs tracked
Our reports highlight the Wavlink WL-NU516U1 router model. The main security themes involve stack-based buffer overflow and OS command injection vulnerabilities found in the `nas.cgi` and `adm.cgi` files. Defenders should immediately focus on CVE-2026-18587, CVE-2026-18588, CVE-2026-18589, and CVE-2026-18590, as these flaws allow remote exploitation. Critically, CVE-2026-18587 and CVE-2026-18590 are unauthenticated OS command injection vulnerabilities that could lead to full device compromise.
Azərbaycanca: Hesabatlarımızda Wavlink WL-NU516U1 model marşrutlaşdırıcısı diqqət mərkəzindədir. Tapılan əsas təhlükəsizlik problemləri `nas.cgi` və `adm.cgi` fayllarında aşkar edilmiş stek əsaslı bufer daşması (buffer overflow) və OS əmr injeksiyası (command injection) zəiflikləridir. Müdafiəçilər CVE-2026-18587, CVE-2026-18588, CVE-2026-18589 və CVE-2026-18590-a xüsusi diqqət yetirməlidirlər, çünki bu qüsurlar uzaqdan istismara imkan verir. Xüsusilə CVE-2026-18587 və CVE-2026-18590 autentifikasiya olmadan cihaz üzərində tam nəzarəti ələ keçirməyə şərait yaradan kritik əmr injeksiyası zəiflikləridir.
This vendor's CVEs4
This hub is built from skopnix's own reporting on Wavlink: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.