CVE-2026-8191
Last modified
CVE-2026-8191 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-bin/adm.cgi. EPSS estimates a 5.34% chance of exploitation in the next 30 days.
Description
A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-bin/adm.cgi. Such manipulation of the argument skiplist1/skiplist2 leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wavlink | Wl-Nu516u1 Firmware | m16u1_v240425 |
References
- https://github.com/wudipjq/my_vuln/blob/main/Wavlink/vuln_4/4.mdExploit, Third Party Advisory
- https://vuldb.com/submit/800730Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/362343Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/362343/ctiPermissions Required, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-8191?
How severe is CVE-2026-8191?
How do I fix CVE-2026-8191?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81904Concrete CMS below 9.5.3 registered view assets for every su…6.3
- CVE-2026-81905Concrete CMS below 9.5.3 stores user validation hashes for m…6.3
- CVE-2026-81906Concrete CMS OAuth callback login path prior to version 9.5.…6.3
- CVE-2026-81907Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Req…7.1
- CVE-2026-81908Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization …6
- CVE-2026-81909Concrete CMS 9 through 9.5.2 is vulnerable to Missing Author…5.9
- CVE-2026-81910Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Te…6.5
- CVE-2026-81911Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored…5.4
- CVE-2026-81912Concrete CMS before 9.5.3 is vulnerable to Cross-Site Reques…5.7
- CVE-2026-81913Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to …6.1
- CVE-2026-81915Concrete CMS below 9.5.3 does not perform an object-level au…5.3
- CVE-2026-81916Concrete CMS before 9.5.3 evaluated the authorization check …4.3
Are you affected by CVE-2026-8191?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
