CVE-2026-49196: Predator Connect W6x: Web Interface Command Injection
The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Predator Connect W6x firmwareto a version that resolves this vulnerability.Fixed in W6x_GBL_2.00.000008 - Compensating control
Until upgraded, avoid using untrusted/unsanitized MAC address values in the Wi-Fi device blocking feature (since MAC input is not properly sanitized and can lead to command injection).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49196?
The severity of CVE-2026-49196 is rated high with a CVSS score of 8.6.
What type of vulnerability is CVE-2026-49196?
CVE-2026-49196 is classified as a command injection vulnerability.
How do I fix CVE-2026-49196?
To fix CVE-2026-49196, upgrade to the firmware version W6x_GBL_2.00.000008.
What is affected by CVE-2026-49196?
CVE-2026-49196 affects the Predator Connect W6x Wi-Fi device.
What issue does CVE-2026-49196 cause?
CVE-2026-49196 allows injection and execution of arbitrary shell commands due to improper sanitization of MAC address input.