Vulnerability Description
A vulnerability has been found in Wavlink WL-NU516U1 240425. This vulnerability affects the function usb_p910 of the file /cgi-bin/adm.cgi. Such manipulation of the argument Pr_mode leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wavlink | Wl-Nu516U1 Firmware | m16u1_v240425 |
| Wavlink | Wl-Nu516U1 | - |
Related Weaknesses (CWE)
References
- https://github.com/jinhao118/cve/blob/main/WAVLINK_2.mdExploitThird Party Advisory
- https://vuldb.com/?ctiid.349551Permissions RequiredVDB Entry
- https://vuldb.com/?id.349551Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.758228Third Party AdvisoryVDB Entry
FAQ
What is CVE-2026-3662?
CVE-2026-3662 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A vulnerability has been found in Wavlink WL-NU516U1 240425. This vulnerability affects the function usb_p910 of the file /cgi-bin/adm.cgi. Such manipulation of the argument Pr_mode leads to command i...
How severe is CVE-2026-3662?
CVE-2026-3662 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-3662?
Check the references section above for vendor advisories and patch information. Affected products include: Wavlink Wl-Nu516U1 Firmware, Wavlink Wl-Nu516U1.