---
id: CVE-2026-13538
title: A vulnerability was determined in Wavlink WL-NU516U1-A M16U1_V240425
summary: >-
  A vulnerability was determined in Wavlink WL-NU516U1-A M16U1_V240425. The
  affected element is the function sub_401D68 of the file /cgi-bin/wireless.cgi
  of the component POST Parameter Handler. This manipulation of the argument
  SSID2G2/SS…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-77
published: '2026-06-29'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13538'
references:
  - url: >-
      https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-06-22-5ccde97-mt7628-squashfs-sysupgrade.bin
    label: cna@vuldb.com
  - url: >-
      https://github.com/Svigo-o/Wavlink_vul/tree/main/wavlink-wl-nu516u1-wireless-multissid-ssid2g2-command-injection
    label: cna@vuldb.com
  - url: >-
      https://github.com/Svigo-o/Wavlink_vul/tree/main/wavlink-wl-nu516u1-wireless-multissid-ssid5g2-command-injection
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-13538'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/834019'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/834021'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/834022'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/834023'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/374546'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/374546/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-06-29T13:42:12.353Z'
epss: 0.02178
epssPercentile: 0.81583
---

## Overview

A vulnerability was determined in Wavlink WL-NU516U1-A M16U1_V240425. The affected element is the function sub_401D68 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. This manipulation of the argument SSID2G2/SSID5G2/AuthMethod2/WPAPSK12 causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
