Shenzhen Yuner WDR201A WiFi Extender Command Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A command injection vulnerability has been identified in the web management interface of the Shenzhen Yuner WDR201A WiFi extender, specifically in hardware version 2.1 and firmware version LFMZX28040922V1.02. The vulnerability arises in the adm.cgi endpoint, where user-supplied input is not properly sanitized before being executed as a command, allowing for arbitrary command execution on the device.

Impact

Exploitation of this vulnerability allows for OS command injection, which can lead to remote code execution on the affected device.

Reproduction

The vulnerability can be reproduced by sending a request to the adm.cgi endpoint with a crafted 'command' parameter that includes the desired OS command. The injected command will be executed by the device's shell, and the output can be retrieved through the web interface.

Added: Mar 18, 2026, 7:11 PM
Updated: Mar 18, 2026, 7:11 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
4.1
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.