Security Advisory

CVE-2026-4166

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-03-15 05:32:08
Last updated 2026-03-17 13:46:28
Assigner VulDB
CVSS score 5.1
State PUBLISHED

Description

A vulnerability was found in Wavlink WL-NU516U1 240425. The impacted element is the function sub_404F68 of the file /cgi-bin/login.cgi. The manipulation of the argument homepage/hostname results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.