CVE 5.3 MEDIUM

Wavlink NU516U1 SetName wireless.cgi sub_403198 command injection_CVE-2025-10962

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This impacts the function sub_403198 of the file /cgi-bin/wireless.cgi of the component SetName Page. The manipulation of the argument mac_5g leads to command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Basic Information

ID CVE-2025-10962
Source VulDB
Published Sep 25, 2025 at 18:32
Modified Sep 25, 2025 at 18:57

Affected Product

Vendor Wavlink
Product NU516U1
Version M16U1_V240425
Affected Versions Wavlink NU516U1 M16U1_V240425

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.