CVE-2023-24796: Vinga Wr-AC1200 Firmware

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

Password vulnerability found in Vinga WR-AC1200 81.102.1.4370 and before allows a remote attacker to execute arbitrary code via the password parameter at the /goform/sysTools and /adm/systools.asp endpoints.

Affected products

  • Vinga Wr-AC1200 Firmware: up to and including 81.102.1.4370

Published 2023-04-26. Last modified 2026-06-17.