WAYOS FBM-220G Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the WAYOS FBM-220G router, specifically in the 24.10.19 firmware version. The issue resides in the 'sub_40F820' function of the 'rc' file, where configuration values related to UPnP are retrieved without proper input sanitization. This flaw allows remote attackers to manipulate these values and execute arbitrary commands on the device. For instance, injecting a command to start a telnet service could be exploited to gain unauthorized access to the router.

Impact

Exploitation of this vulnerability allows for command injection, where an attacker can execute arbitrary commands on the device. This could lead to remote code execution and full compromise of the router.

Reproduction

To reproduce this vulnerability, modify the UPnP-related configuration values 'upnp_waniface', 'upnp_ssdp_interval', and 'upnp_max_age' in the router's firmware version 24.10.19. The 'sub_40F820' function will then use these unsanitized values to construct a command that is executed on the system. This can be done by injecting a command into the 'upnp_waniface' parameter, for example, by setting it to '0$(telnetd)', which would start the telnet service upon reboot.

Added: Feb 16, 2026, 9:36 AM
Updated: Feb 16, 2026, 9:36 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.1
remediation
0.0
relevance
2.9
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.