← All CVEs

CVE-2026-30702

critical · 9.8

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, allowing attackers to bypass authentication by directly accessing restricted web application endpoints through forced browsing

9.8
CVSS
0.4%
EPSS (exploit prob.)
31st
EPSS percentile
2026-03-18
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-285

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-30702