CVE-2026-3612Disclosure(wavlink / wl-nu516u1)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/adm.cgi of the component OTA Online Upgrade. This manipulation of the argument firmware_url causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wl-nu516u1
  • wl-nu516u1_firmware

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-06); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
wl-nu516u1wl-nu516u1_firmware

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-06: 3Mentions · 2026-03-07: 1Mentions · 2026-03-11: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-11: 103-0603-0703-11
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-063
Disclosure3
2026-03-071
Disclosure1
2026-03-111
Disclosure1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3612 (CVSS:7.3, HIGH) is Analyzed. A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/..https://nvd.nist.gov/vuln/detail/CVE-2026-3612 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE-2026-3612, a high‑severity vulnerability in Wavlink WL‑NU516U1 routers affecting sub_405AF4 in the /cgi‑bin file, with no evidence of exploitation or patch information.

    0000014
    172 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3612 - Wavlink - WL-NU516U1 - https://www.redpacketsecurity.com/cve-alert-cve-2026-3612-wavlink-wl-nu516u1/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3612 #wavlink #wl-nu516u1

    Post summary

    The tweet announces CVE-2026-3612 affecting Wavlink WL-NU516U1, providing a link to a security alert for additional details.

    0000069
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3612 A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/adm.cgi of the component OTA Online Upgrade. Thi… https://www.cve.org/CVERecord?id=CVE-2026-3612

    Post summary

    A new vulnerability (CVE-2026-3612) has been identified in the OTA Online Upgrade component of Wavlink WL-NU516U1, affecting a specific CGI function, with no PoC, exploit, or patch details provided.

    00000133
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3612 Command Injection Vulnerability in Wavlink WL-NU516U1 Router via Firmware URL https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3612

    Post summary

    Short notice indicating a command injection vulnerability in a Wavlink router, with minimal details and a link to a vulnerability page.

    0000048
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3612 Intel Report: https://ift.tt/zhUmi1M

    Post summary

    A brief alert announcing the existence of CVE-2026-3612, with no further technical or remediation details.

    0000045
    343 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWwavlinkwl-nu516u1---
OSwavlinkwl-nu516u1_firmwarem16u1_v240425--

Explore more