CVE-2026-2615

Plain English Summary

AI-powered analysis for quick understanding

An attacker can remotely execute malicious commands on the Wavlink WL-NU516U1 device by exploiting a flaw in its firewall settings. This vulnerability can be triggered by manipulating a specific input, and it affects devices with firmware versions up to December 8, 2025.

Technical Description

A flaw has been found in Wavlink WL-NU516U1 up to 20251208. The affected element is the function singlePortForwardDelete of the file /cgi-bin/firewall.cgi. Executing a manipulation of the argument del_flag can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeChanged

Vector String

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$1,632($1K-$5K)
Vendor Response
Grade APatched in 1 day

Quick Information

Published

Feb 17, 2026

about 2 months ago

Last Modified

Feb 18, 2026

about 2 months ago

Vendor

wavlink

Product

wl-nu516u1 firmware

Related Vulnerabilities

CVE-2026-3716Medium

This vulnerability allows an attacker to execute cross-site scripting (XSS) attacks remotely by manipulating the Hostname argument in the device's firmware. To exploit this, the attacker needs to send a specially crafted request to the affected device, which can lead to unauthorized actions or data theft from users interacting with the device.

CVE-2026-3715High

An attacker can remotely exploit a vulnerability in the Wavlink WL-WN579X3-C firmware to execute arbitrary code on the device by manipulating a specific setting, which could lead to full control over the device. To protect against this risk, users should upgrade to the latest firmware version as soon as possible.

CVE-2026-3662Medium

An attacker can remotely execute commands on the Wavlink WL-NU516U1 device by manipulating a specific setting in its firmware. This vulnerability requires no special access, making it a significant risk for anyone using this device.

CVE-2026-3661Medium

An attacker can remotely execute arbitrary commands on the Wavlink WL-NU516U1 device due to a flaw in its firmware that allows them to manipulate a specific function. This vulnerability requires no special access, making it relatively easy for an attacker to exploit if they know how.

CVE-2026-2565Medium

This vulnerability allows an attacker to remotely crash the Wavlink WL-NU516U1 device or potentially take control of it by exploiting a flaw in how the device handles time zone settings. Although the attack is complex and difficult to execute, public exploit code is available, making it a real threat to unpatched devices.