CVE-2025-10959 | Wavlink NU516U1 M16U1_V240425 /cgi-bin/firewall.cgi sub_401778 dmz_flag command injection
A vulnerability was found in Wavlink NU516U1 M16U1_V240425 and classified as critical. The affected element is the function sub_401778 of the file /cgi-bin/firewall.cgi. Such manipulation of the argument dmz_flag leads to command injection.
This vulnerability is documented as CVE-2025-10959. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More