CVE-2026-8230Active Exploitation(wavlink / wl-nu516u1)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch wavlink wl-nu516u1 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wl-nu516u1
  • wl-nu516u1_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
wl-nu516u1wl-nu516u1_firmware

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-10: 2Active Exploitation · 2026-05-10: 1Patch / Workaround · 2026-05-10: 1Technical Details · 2026-05-10: 205-10
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-8230 A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argumen… https://www.cve.org/CVERecord?id=CVE-2026-8230

    Post summary

    A flaw has been identified in the Wavlink NU516U1 device affecting the sys_login1 function in /cgi-bin/login.cgi; no exploit, patch, or active exploitation details are provided.

    00000119
    57.5K followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    ⚠️ CVE-2026-8230 in Wavlink NU516U1 is under active exploitation, allowing attackers to inject OS commands via login.cgi. This could lead to full system compromise. Patch now to protect your systems. #NerdieNews #CyberSecurity #InfoSec #Vulnerability https://t.co/keIuKchbGJ

    Post summary

    CVE-2026-8230 in Wavlink NU516U1 is reportedly being actively exploited in the wild, enabling OS command injection via login.cgi. A patch is available to mitigate the risk.

    0000027
    59 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWwavlinkwl-nu516u1---
OSwavlinkwl-nu516u1_firmwarem16u1_v240425--

Explore more