Vulnerability Description
The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, allowing attackers to bypass authentication by directly accessing restricted web application endpoints through forced browsing
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://mstreet97.github.io/security-research/iot/vulnerability-disclosure/cyber
- https://www.made-in-china.com/showroom/yeapook/#:~:text=Established%20in%202015.
- https://mstreet97.github.io/security-research/iot/vulnerability-disclosure/cyber
FAQ
What is CVE-2026-30702?
CVE-2026-30702 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, al...
How severe is CVE-2026-30702?
CVE-2026-30702 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-30702?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.