Executive brief
The WDR201A WiFi Extender, a consumer device used to expand wireless network coverage, contains a critical security flaw. An unauthenticated attacker can remotely take full control of the device by sending specially crafted network requests. This could allow an attacker to intercept network traffic, disrupt internet connectivity, or use the device as a foothold to attack other systems on the local network.
Technical details
An OS command injection vulnerability exists in the `wireless.cgi` binary of the WDR201A WiFi Extender. The issue stems from the lack of sanitization of the `sz11gChannel` and `PIN` POST parameters within the `set_wifi_basic` and `set_wifi_do_wps` functions, respectively. These parameters are retrieved via `web_get()` and passed directly into a `do_system()` call (which wraps the `system()` function) to execute shell commands like `iwpriv`. An unauthenticated remote attacker can exploit this by injecting shell metacharacters (e.g., semicolons) into these parameters to achieve arbitrary remote code execution (RCE) with the privileges of the web server.
Affected products
- Shenzhen Yuner Yipu Trading Co., Ltd WDR201A WiFi Extender HW V2.1, FW LFMZX28040922V1.02
Timeline
- 2026-05-04: disclosed: Vulnerability disclosed by researchers Matteo Strada and Daniele Berardinelli
- 2026-05-04: advisory
References
- https://mstreet97.github.io/security-research/iot/vulnerability-disclosure/ai-assisted-research/cybersecurity/cve/2026/05/04/Teaching_the_Machine_Where_to_Look.html
- https://www.made-in-china.com/showroom/yeapook/
- https://www.vulncheck.com/advisories/wdr201a-wifi-extender-os-command-injection-via-wireless-cgi