CVE-2026-4166Disclosure

LOWCVSS 2.0 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in Wavlink WL-NU516U1 240425. The impacted element is the function sub_404F68 of the file /cgi-bin/login.cgi. The manipulation of the argument homepage/hostname results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-15: 2Technical Details · 2026-03-15: 203-15
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4166 A vulnerability was found in Wavlink WL-NU516U1 240425. The impacted element is the function sub_404F68 of the file /cgi-bin/login.cgi. The manipulation of the argument… https://www.cve.org/CVERecord?id=CVE-2026-4166

    Post summary

    The entry announces CVE-2026-4166, a vulnerability in the /cgi-bin/login.cgi function of the Wavlink WL-NU516U1, and references the official CVE record.

    00000109
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4166 - Wavlink WL-NU516U1 login.cgi sub_404F68 cross site scripting Intel Report: https://ift.tt/W9i7fN5

    Post summary

    An alert announcing CVE-2026-4166, a cross‑site scripting flaw in Wavlink WL‑NU516U1’s login.cgi, providing minimal technical details but no PoC, exploit, or patch information.

    0000031
    336 followersView on X

Explore more