CVE-2026-13538Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Wavlink WL-NU516U1-A M16U1_V240425. The affected element is the function sub_401D68 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. This manipulation of the argument SSID2G2/SSID5G2/AuthMethod2/WPAPSK12 causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-29: 3Technical Details · 2026-06-29: 206-29
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-13538 Command Injection in Wavlink WL-NU516U1-A M16U1_V240425 POST Parameter Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13538

    Post summary

    The text merely cites a CVE number and its title without any details on exploitation, mitigation, or technical characteristics.

    00010140
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13538 A vulnerability was determined in Wavlink WL-NU516U1-A M16U1_V240425. The affected element is the function sub_401D68 of the file /cgi-bin/wireless.cgi of the compone… https://www.cve.org/CVERecord?id=CVE-2026-13538 ----- Traducción: Se determinó una v… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-13538, noting the affected function and file, but provides no PoC, exploit, active exploitation, or patch information.

    0000032
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-13538 A vulnerability was determined in Wavlink WL-NU516U1-A M16U1_V240425. The affected element is the function sub_401D68 of the file /cgi-bin/wireless.cgi of the compone… https://www.cve.org/CVERecord?id=CVE-2026-13538

    Post summary

    The text announces CVE-2026-13538, describing a vulnerability in a specific function of Wavlink firmware, with no evidence of PoC, exploitation, or available fixes.

    00000715
    57.7K followersView on X

Explore more