LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-30702

Published
CVSS9.8
Severitycritical
WeaknessCWE-285
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, allowing attackers to bypass authentication by directly accessing restricted web application endpoints through forced browsing

References

← Back to the CVE Tracker

Our coverage of CVE-2026-30702

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-30702.