CVE-2025-10958 | Wavlink NU516U1 M16U1_V240425 AddMac Page /cgi-bin/wireless.cgi sub_403010 macAddr command injection
A vulnerability has been found in Wavlink NU516U1 M16U1_V240425 and classified as critical. Impacted is the function sub_403010 of the file /cgi-bin/wireless.cgi of the component AddMac Page. This manipulation of the argument macAddr causes command injection.
This vulnerability is registered as CVE-2025-10958. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More