CVE-2026-3662 | Wavlink WL-NU516U1 240425 /cgi-bin/adm.cgi usb_p910 Pr_mode command injection (EUVD-2026-10142)
A vulnerability described as critical has been identified in Wavlink WL-NU516U1 240425. This vulnerability affects the function usb_p910 of the file /cgi-bin/adm.cgi. Such manipulation of the argument Pr_mode leads to command injection.
This vulnerability is referenced as CVE-2026-3662. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure.