A command injection vulnerability in RG-EW series home routers and repeaters v.EW3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH3.0(1)B11P219, RG-EG series business VPN routers v.EG3.0(1)B11P219, EAP and RAP series wireless access points v.AP3.0(1)B11P219, and NBC series wireless controllers v.AC3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /cgi-bin/luci/api/cmd via the remoteIp field.
RG-EW1200G PRO Wireless Routers EW3.0(1)B11P204, RG-EW1800GX PRO Wireless Routers EW3.0(1)B11P204, and RG-EW3200GX PRO Wireless Routers EW3.0(1)B11P204 were discovered to contain multiple command injection vulnerabilities via the data.ip, data.protocal, data.iface and data.package parameters in the runPackDiagnose function of diagnose.lua.