CVE-2026-3612: Wavlink WL-NU516U1 OTA Online Upgrade adm.cgi sub_405AF4 command injection
A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub405AF4 of the file /cgi-bin/adm.cgi of the component OTA Online Upgrade. This manipulation of the argument firmwareurl causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3612?
CVE-2026-3612 has a high severity rating due to its command injection vulnerability that can lead to unauthorized access and control of the affected system.
How do I fix CVE-2026-3612?
To fix CVE-2026-3612, update the Wavlink WL-NU516U1 device firmware to the latest version provided by Wavlink.
What component is affected by CVE-2026-3612?
CVE-2026-3612 affects the OTA Online Upgrade functionality in the adm.cgi component of the Wavlink WL-NU516U1.
What type of vulnerability is CVE-2026-3612?
CVE-2026-3612 is classified as a command injection vulnerability.
Which version of Wavlink WL-NU516U1 is vulnerable to CVE-2026-3612?
The vulnerability CVE-2026-3612 is specifically identified in the Wavlink WL-NU516U1 version V240425.