PT-2026-36914 · Unknown · Wifi Extender Wdr201A

Matteo Strada

·

Published

2026-05-04

·

Updated

2026-05-04

·

CVE-2026-41926

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02)
Description An OS command injection issue exists in the firewall.cgi binary across five request handlers due to insufficient input validation. Attackers can inject arbitrary shell commands using subshell syntax or unfiltered parameters. The affected parameters include websURLFilter, websHostFilter, portForward, singlePortForward, and ipportFilter. Injected payloads persist in NVRAM and re-execute during every subsequent request to firewall.cgi.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-41926

Affected Products

Wifi Extender Wdr201A