Wavlink Vulnerabilities
Wavlink sells home and business networking equipment such as Wi-Fi routers, mesh systems, outdoor access points and USB adapters, along with PC docking peripherals. The database tracks 19 Wavlink CVE records. None of them are in the CISA KEV catalog. They are listed because of exploitation signals such as a high EPSS score or a public exploit reference. The most affected products are NU516U1, WL-NU516U1, WL-WN579A3.
Affected Products
4 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| NU516U1 | 10 | - | 2026-05-10 |
| WL-NU516U1 | 4 | - | 2026-03-07 |
| WL-WN579A3 | 4 | - | 2026-02-16 |
| WL-WN570HA1 | 1 | - | 2026-05-03 |
Security Advisories
Weakness Types
All Wavlink CVEs
19 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-3661 | Wavlink WL-NU516U1 adm.cgi ota_new_upgrade command injection | Wavlink | 5.8 | 11.3% | 2026-03-07 | |
| CVE-2026-3662 | Wavlink WL-NU516U1 adm.cgi usb_p910 command injection | Wavlink | 5.8 | 11.3% | 2026-03-07 | |
| CVE-2026-3612 | Wavlink WL-NU516U1 OTA Online Upgrade adm.cgi sub_405AF4 command injection | Wavlink | 8.6 | 10.4% | 2026-03-06 | |
| CVE-2026-2527 | Wavlink WL-WN579A3 login.cgi command injection | Wavlink | 6.5 | 8.7% | 2026-02-16 | |
| CVE-2026-8188 | Wavlink NU516U1 adm.cgi change_wifi_password os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8189 | Wavlink NU516U1 adm.cgi wzdrepeater os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8190 | Wavlink NU516U1 adm.cgi wan os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8191 | Wavlink NU516U1 adm.cgi wifi_region os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8192 | Wavlink NU516U1 adm.cgi wzdap os command injection | Wavlink | 6.5 | 8.5% | 2026-05-09 | |
| CVE-2026-8227 | Wavlink NU516U1 adm.cgi wzdapMesh os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-8228 | Wavlink NU516U1 wireless.cgi advance os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-8229 | Wavlink NU516U1 wireless.cgi WifiBasic os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-8230 | Wavlink NU516U1 login.cgi sys_login1 os command injection | Wavlink | 6.5 | 8.5% | 2026-05-10 | |
| CVE-2026-2528 | Wavlink WL-WN579A3 wireless.cgi Delete_Mac_list command injection | Wavlink | 6.5 | 8.4% | 2026-02-16 | |
| CVE-2026-2526 | Wavlink WL-WN579A3 wireless.cgi multi_ssid command injection | Wavlink | 6.5 | 8.4% | 2026-02-16 | |
| CVE-2026-2530 | Wavlink WL-WN579A3 wireless.cgi AddMac command injection | Wavlink | 6.5 | 8.4% | 2026-02-16 | |
| CVE-2026-2615 | Wavlink WL-NU516U1 firewall.cgi singlePortForwardDelete command injection | Wavlink | 8.6 | 8.0% | 2026-02-17 | |
| CVE-2026-7690 | Wavlink WL-WN570HA1 adm.cgi set_sys_adm command injection | Wavlink | 6.5 | 6.0% | 2026-05-03 | |
| CVE-2026-3704 | Wavlink NU516U1 Incomplete Fix CVE-2025-10959 firewall.cgi sub_405B2C command injection | Wavlink | 5.8 | 5.5% | 2026-03-08 |
Frequently Asked Questions
How many Wavlink vulnerabilities are actively exploited?→
0 Wavlink CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09.
Which Wavlink products have the most exploited vulnerabilities?→
- +NU516U1: 10 CVEs (0 in KEV)
- +WL-NU516U1: 4 CVEs (0 in KEV)
- +WL-WN579A3: 4 CVEs (0 in KEV)
- +WL-WN570HA1: 1 CVE (0 in KEV)
Where does Wavlink publish security advisories?→
Wavlink publishes security advisories at https://www.wavlink.com/en_us/security.html. Check the vendor advisory for fixed versions and workarounds before applying updates.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Wavlink, MITRE, CISA, or FIRST.