CVE-2026-3662: Wavlink WL-NU516U1 adm.cgi usb_p910 command injection
A vulnerability has been found in Wavlink WL-NU516U1 240425. This vulnerability affects the function usbp910 of the file /cgi-bin/adm.cgi. Such manipulation of the argument Prmode leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3662?
CVE-2026-3662 is classified as a high severity vulnerability due to the potential for command injection.
How do I fix CVE-2026-3662?
To fix CVE-2026-3662, it is recommended to update the Wavlink WL-NU516U1 firmware to the latest version provided by the vendor.
What does CVE-2026-3662 affect?
CVE-2026-3662 affects the command injection vulnerability in the usb_p910 function of the /cgi-bin/adm.cgi file on the Wavlink WL-NU516U1 device.
Who is affected by CVE-2026-3662?
Users and administrators using the Wavlink WL-NU516U1 model are affected by CVE-2026-3662.
Can CVE-2026-3662 be exploited remotely?
Yes, CVE-2026-3662 can be exploited remotely if the attacker manipulates the Pr_mode argument.