Vulnerability Description
A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cgi-bin/wireless.cgi. This manipulation of the argument Guest_ssid causes command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wavlink | Wl-Nu516U1 Firmware | m16u1_v240425 |
| Wavlink | Wl-Nu516U1 | - |
Related Weaknesses (CWE)
References
- https://github.com/lin-3-start/lin-cve/blob/main/Wavlink/Wavlink.mdExploitThird Party Advisory
- https://github.com/lin-3-start/lin-cve/blob/main/Wavlink/Wavlink.md#pocExploitThird Party Advisory
- https://vuldb.com/?ctiid.320528Permissions RequiredVDB Entry
- https://vuldb.com/?id.320528Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.629181Third Party AdvisoryVDB Entry
FAQ
What is CVE-2025-9149?
CVE-2025-9149 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cgi-bin/wireless.cgi. This manipulation of the argument Guest_ssid causes command ...
How severe is CVE-2025-9149?
CVE-2025-9149 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-9149?
Check the references section above for vendor advisories and patch information. Affected products include: Wavlink Wl-Nu516U1 Firmware, Wavlink Wl-Nu516U1.