CVE-2026-30702
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, allowing attackers to bypass authentication by directly accessing restricted web application endpoints through forced browsing
Published 2026-03-18. Last modified 2026-06-17.