CVE-2026-30702: Critical severity TP-Link WDR201A vulnerability
The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, allowing attackers to bypass authentication by directly accessing restricted web application endpoints through forced browsing
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30702?
CVE-2026-30702 is classified as a high severity vulnerability due to its potential for unauthorized access to sensitive functions in the device.
How do I fix CVE-2026-30702?
To mitigate CVE-2026-30702, update the firmware of the TP-Link WDR201A to the latest version that addresses this authentication issue.
What systems are affected by CVE-2026-30702?
CVE-2026-30702 specifically affects the TP-Link WDR201A WiFi Extender with hardware version V2.1 and firmware LFMZX28040922V1.02.
What kind of attacks can exploit CVE-2026-30702?
Attackers can exploit CVE-2026-30702 to bypass authentication and gain unauthorized access to restricted web application endpoints.
Is there a workaround for CVE-2026-30702 if I can't update my device?
If unable to update, consider limiting network access to the device and using strong network security practices to reduce exposure.