CVE-2025-10960 | Wavlink NU516U1 M16U1_V240425 DeleteMac Page /cgi-bin/wireless.cgi sub_402D1C delete_list command injection
A vulnerability was found in Wavlink NU516U1 M16U1_V240425. It has been classified as critical. The impacted element is the function sub_402D1C of the file /cgi-bin/wireless.cgi of the component DeleteMac Page. Performing manipulation of the argument delete_list results in command injection.
This vulnerability is reported as CVE-2025-10960. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.