Shenzhen Yuner WDR201A WiFi Extender Command Injection Vulnerability Allowing Remote Code Execution
Vulnerability
A command injection vulnerability has been identified in the web management interface of the Shenzhen Yuner WDR201A WiFi extender, specifically in hardware version 2.1 and firmware version LFMZX28040922V1.02. The vulnerability arises in the adm.cgi endpoint, where user-supplied input is not properly sanitized before being executed as a command, allowing for arbitrary command execution on the device.
Impact
Exploitation of this vulnerability allows for OS command injection, which can lead to remote code execution on the affected device.
Reproduction
The vulnerability can be reproduced by sending a request to the adm.cgi endpoint with a crafted 'command' parameter that includes the desired OS command. The injected command will be executed by the device's shell, and the output can be retrieved through the web interface.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
