Description

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi binary's reboot_time function that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the reboot_time POST parameter. Attackers can send a crafted request with shell metacharacters in the reboot_time parameter when reboot_enabled=1 to achieve remote code execution.

INFO

Published Date :

2026-05-04T19:15:43.966Z

Last Modified :

2026-05-08T14:05:49.691Z

Source :

VulnCheck
AFFECTED PRODUCTS

The following products are affected by CVE-2026-41925 vulnerability.

Vendors Products
Shenzhen Yuner Yipu
  • Wifi Extender Wdr201a

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability