CVE-2026-30703: Command Injection
A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02). The adm.cgi endpoint improperly sanitizes user-supplied input provided to a command-related parameter in the sysCMD functionality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30703?
CVE-2026-30703 is classified as a high severity command injection vulnerability.
How do I fix CVE-2026-30703?
To fix CVE-2026-30703, update the firmware of the WiFi Extender WDR201A to the latest version provided by TP-Link.
What systems are affected by CVE-2026-30703?
CVE-2026-30703 affects the TP-Link WiFi Extender WDR201A with firmware LFMZX28040922V1.02.
What are the potential impacts of CVE-2026-30703?
CVE-2026-30703 may allow an attacker to execute arbitrary commands on the device through the web management interface.
Is CVE-2026-30703 exploitable remotely?
Yes, CVE-2026-30703 can be exploited remotely if the web management interface is accessible over the internet.