CVE-2026-4166
Published
CVSS v3
3.5
LOW
CVSS v2
4
MEDIUM
Affected
1
PROJECT
Description
A vulnerability was found in Wavlink WL-NU516U1 240425. The impacted element is the function sub_404F68 of the file /cgi-bin/login.cgi. The manipulation of the argument homepage/hostname results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.