The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, allowing attackers to bypass authentication by directly accessing restricted web application endpoints through forced browsing
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-18 18:16
Updated : 2026-06-17 10:32
NVD link : CVE-2026-30702
Mitre link : CVE-2026-30702
CVE.ORG link : CVE-2026-30702
JSON object : View
Products Affected
No product.
CWE
CWE-285
Improper Authorization
