A vulnerability categorized as critical has been discovered in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of the argument Password can lead to os command injection.
The identification of this vulnerability is CVE-2026-18587. The attack may be launched remotely. Furthermore, there is an exploit available.
It is advisable to upgrade the affected component.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.