Description

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, allowing attackers to bypass authentication by directly accessing restricted web application endpoints through forced browsing

INFO

Published Date :

2026-03-18T00:00:00.000Z

Last Modified :

2026-03-23T15:56:47.034Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2026-30702 vulnerability.

Vendors Products
Shenzhen Yuner Yipu
  • Wdr201a

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact