
CVE-2026-41925 WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi binary's reboot_time function that allows unauthe… https://www.cve.org/CVERecord?id=CVE-2026-41925
Post summary
A new OS command injection vulnerability (CVE‑2026‑41925) was disclosed in the WDR201A WiFi Extender’s adm.cgi binary, allowing unauthenticated command execution.


