Executive brief
The PowerStick Wave Dual-Band Wifi Extender, a device used to expand wireless network coverage, contains a security flaw that allows an authorized user to take full control of the hardware. By sending a specially crafted request to the device's management interface, an attacker with valid login credentials can execute unauthorized commands. This could lead to the interception of network traffic, the installation of malicious software, or the use of the device as a foothold for further attacks on the local network.
Technical details
An OS command injection vulnerability (CWE-78) exists in the PowerStick Wave Dual-Band Wifi Extender V1.0 within the /cgi-bin/cgi_vista.cgi executable. The flaw is caused by insufficient sanitization of user-supplied input in the 'time_zone' parameter of a JSON payload when configuring NTP settings (command ID 55). An authenticated attacker can exploit this by sending a crafted HTTP POST request containing shell metacharacters (e.g., ';<command>') to execute arbitrary system-level commands with root privileges. While a proof-of-concept exists, no official patch has been confirmed; users are advised to use strong unique passwords or replace the device.
Affected products
- PowerStick Wave Dual-Band Wifi Extender V1.0
Timeline
- 2025-07-26: disclosed: Initial discovery and Gist publication by researcher
- 2025-07-28: advisory: CVE published to NVD