wavlink has 4 CVEs on record. The busiest recent month was May 2026 with 4. The median CVSS is 6.3 (medium). The dominant weakness classes are CWE-77 (4) and CWE-78 (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 0 prev 4
Worst active — by depth score
CVE-2026-8230Medium· 6.3A flaw has been found in Wavlink NU516U1 24042536CVE-2026-8229Medium· 6.3A vulnerability was detected in Wavlink NU516U1 24042536CVE-2026-8228Medium· 6.3A security vulnerability has been detected in Wavlink NU516U1 24042536CVE-2026-8227Medium· 6.3A weakness has been identified in Wavlink NU516U1 24042536
wavlink vulnerabilities
CVEs affecting wavlink, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-8230Medium· 6.3A flaw has been found in Wavlink NU516U1 240425
A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to os command injection. The attack can be executed…
CVE-2026-8229Medium· 6.3A vulnerability was detected in Wavlink NU516U1 240425
A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument AuthMethod/EncrypType results in os command injection. Re…
CVE-2026-8228Medium· 6.3A security vulnerability has been detected in Wavlink NU516U1 240425
A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/ieee_80211h leads to os command inject…
CVE-2026-8227Medium· 6.3A weakness has been identified in Wavlink NU516U1 240425
A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation causes os command injection. The attack may be initiated remotely. The exploit has been m…