CVE 8.6 HIGH

Wavlink WL-NU516U1 firewall.cgi singlePortForwardDelete command injection_CVE-2026-2615

8.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Description

A flaw has been found in Wavlink WL-NU516U1 up to 20251208. The affected element is the function singlePortForwardDelete of the file /cgi-bin/firewall.cgi. Executing a manipulation of the argument del_flag can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

AI Analysis

Command injection vulnerability in Wavlink WL-NU516U1 firewall.cgi via singlePortForwardDelete function

Basic Information

ID CVE-2026-2615
Source VulDB
Published Feb 17, 2026 at 13:02

Affected Product

Vendor Wavlink
Product WL-NU516U1
Version 20251208
Affected Versions Wavlink WL-NU516U1 20251208

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor Wavlink
Product WL-NU516U1
Version 20251208

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.