CVE-2026-2548Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in WAYOS FBM-220G 24.10.19. This affects the function sub_40F820 of the file rc. Executing a manipulation of the argument upnp_waniface/upnp_ssdp_interval/upnp_max_age can lead to command injection. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-18: 1Technical Details · 2026-02-18: 102-18
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Cybersecurity Aide@SecAideInfo
    Disclosure

    🚨 #CyberAlert: CVE-2026-2548 in WAYOS FBM-220G (v24.10.19) enables remote command injection via the upnp_waniface/upnp_ssdp_interval/upnp_max_age args in rc. ⚠️ Vendor unresponsive. Take action now to secure your systems! 🔒 #CyberSecurity #PatchNow #Infosec

    Post summary

    The post announces a new vulnerability (CVE‑2026‑2548) in WAYOS FBM‑220G that permits remote command injection via specific rc arguments, with no patch, PoC, or active exploitation mentioned.

    0000025
    20 followersView on X

Explore more