CVE-2026-2548: Wayos Fbm-220g

Medium severity, CVSS 6.3. EPSS: 2.5% chance of exploitation in the next 30 days.

A flaw has been found in WAYOS FBM-220G 24.10.19. This affects the function sub_40F820 of the file rc. Executing a manipulation of the argument upnp_waniface/upnp_ssdp_interval/upnp_max_age can lead to command injection. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

  • Wayos Fbm-220g: version 24.10.19 only

Published 2026-02-16. Last modified 2026-06-17.