CVE-2026-30704: Critical severity TP-Link WiFi Extender WDR201A vulnerability
The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30704?
CVE-2026-30704 is considered a high severity vulnerability due to its potential for unauthorized access through an unprotected UART interface.
How do I fix CVE-2026-30704?
To mitigate CVE-2026-30704, secure the UART interface by disabling it or restricting access to authorized personnel only.
What are the potential risks of CVE-2026-30704?
CVE-2026-30704 could allow attackers to gain low-level access to the device, potentially leading to further exploitation or data breaches.
Who is affected by CVE-2026-30704?
The vulnerability affects users of the TP-Link WiFi Extender WDR201A, specifically hardware version V2.1 with firmware LFMZX28040922V1.02.
Is there a patch available for CVE-2026-30704?
As of now, there is no official patch released for CVE-2026-30704, so manual mitigation steps are recommended.