PT-2026-26109 · D Link · Wifi Extender Wdr201A

Mstreet97

·

Published

2026-03-18

·

Updated

2026-03-19

·

CVE-2026-30703

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02)
Description A command injection issue exists in the web management interface. The adm.cgi endpoint does not properly sanitize user-supplied input for a command-related parameter within the sysCMD functionality. This could allow for unauthorized command execution.
Recommendations Apply updates to address the improper input sanitization in the adm.cgi endpoint and the sysCMD functionality.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-30703

Affected Products

Wifi Extender Wdr201A