CVE-2026-8228
Last modified
CVE-2026-8228 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. EPSS estimates a 4.81% chance of exploitation in the next 30 days.
Description
A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/ieee_80211h leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wavlink | Wl-Nu516u1 Firmware | m16u1_v240425 |
References
- https://github.com/wudipjq/my_vuln/blob/main/Wavlink/vuln_7/7.mdExploit, Third Party Advisory
- https://vuldb.com/submit/800733Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/362445Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/362445/ctiPermissions Required, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-8228?
How severe is CVE-2026-8228?
How do I fix CVE-2026-8228?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-82274Twenty through 2.35.0 contains an open redirect vulnerabilit…4.7
- CVE-2026-82275Qwen-Agent through 0.0.34 contains a path traversal vulnerab…7.5
- CVE-2026-82276StarRocks through 4.0.13 contains an authentication bypass v…5.3
- CVE-2026-82277Argo Rollouts dashboard through 1.10.0 binds to all interfac…9.8
- CVE-2026-82278BISHENG before 2.6.0 contains a remote code execution vulner…8.8
- CVE-2026-82279HyperDX through 1.10.1 fails to enforce role-based access co…8.1
- CVE-2026-82280Quivr through 0.0.322 fails to validate ownership in prompt …7.1
- CVE-2026-82281Kotaemon through 0.12.0 fails to properly validate conversat…7.4
- CVE-2026-82282Atlantis through 0.47.1 fails to authenticate the /github-ap…8
- CVE-2026-82283VoltAgent through 2.1.20 fails to validate conversation owne…8.1
- CVE-2026-82284Quivr versions through 0.0.322 fail to validate chat ownersh…8.1
- CVE-2026-82285bisheng through 2.6.0-fix2 contains a server-side request fo…8.2
Are you affected by CVE-2026-8228?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
