CVE-2026-2017Disclosure(ip-com / w30ap)

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in IP-COM W30AP up to 1.0.0.11(1340). Affected by this issue is the function R7WebsSecurityHandler of the file /goform/wx3auth of the component POST Request Handler. The manipulation of the argument data results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • w30ap
  • w30ap_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Exploit: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-02-06); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
w30apw30ap_firmware

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-06: 3Mentions · 2026-02-11: 1PoC Mentioned / Linked · 2026-02-06: 1Technical Details · 2026-02-06: 2Technical Details · 2026-02-11: 102-0602-11
Signal classification3 categories
Disclosure
250.0%
Exploit
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-063
Disclosure1Exploit1General1
2026-02-111
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    General

    CVE-2026-2017 A vulnerability was detected in IP-COM W30AP up to 1.0.0.11(1340). Affected by this issue is the function R7WebsSecurityHandler of the file /goform/wx3auth of the compo… https://www.cve.org/CVERecord?id=CVE-2026-2017

    Post summary

    The excerpt merely notes that CVE‑2026‑2017 affects IP‑COM W30AP, mentioning a function and file path, without providing further technical detail, patches, or exploitation evidence.

    00020211
    56.5K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2017 (CVSS:8.9, CRITICAL) is Awaiting Analysis. A vulnerability was detected in IP-COM W30AP up to 1.0.0.11(1340). Affected by this issue is the function R7WebsSecurity..https://nvd.nist.gov/vuln/detail/CVE-2026-2017 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A critical vulnerability (CVE-2026-2017) has been identified in IP-COM W30AP, affecting the R7WebsSecurity function; the issue is awaiting analysis and no PoC, exploit, or patch information is currently available.

    0000040
    171 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2017: CRITICAL] Critical vulnerability alert: IP-COM W30AP up to 1.0.0.11(1340) exposed to remote stack-based buffer overflow attack via R7WebsSecurityHandler in POST Request Handler component. Attac...#cve,CVE-2026-2017,#cybersecurity https://cvefind.com/CVE-2026-2017

    Post summary

    A critical stack-based buffer overflow vulnerability in IP-COM W30AP devices is disclosed, but no PoC, exploit, patch, or active exploitation is reported.

    0000058
    583 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-2017: IP-COM W30AP POST Request wx3auth... Remote exploitation of IP-COM W30AP's R7WebsSecurityHandler delivers unauthenticated RCE via POST to /goform/wx3auth - v... https://zerodaysignal.com/vulnerability/CVE-2026-2017 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑2017, describing how an unauthenticated RCE can be achieved via a specific POST request and links to a site that likely contains a PoC.

    0000057
    132 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWip-comw30ap4.0--
OSip-comw30ap_firmware---

Explore more