CVE-2026-30702
Essential information
- Published
- 18/03/2026 18:16
- Modified
- 19/03/2026 13:25
- Author
- —
- Creator
- —
- CISA KEV
- No
- CWE
- —
- CVSS vector
- — — —
Description
The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, allowing attackers to bypass authentication by directly accessing restricted web application endpoints through forced browsing
NVD status
- Status
- Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
- Source
- [email protected]
- NVD
- View on NVD
Affected products (CPE)
| Product | CPE |
|---|---|
| manufacturer / wifi extender wdr201a | cpe:2.3:a:manufacturer:wifi_extender_wdr201a:1.02:*:*:*:*:*:*:* |