Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2310 articles · 131407 vulns · 35/41 feeds (7d)
← Back to list
—
CVE-2026-41924EXPLOITED
shenzhen yipu commercial and trading co. · wdr201a wifi extender

WDR201A WiFi Extender OS Command Injection via makeRequest.cgi

Description

A vulnerability, classified as critical, was found in Yipu WDR201A WiFi Extender up to 1.02. Affected by this vulnerability is the function set_time/StartSniffer of the file makeRequest.cgi of the component POST Request Handler. The manipulation results in OS command injection. This vulnerability is known as CVE-2026-41924. It is possible to launch the attack remotely.

Affected Products

VendorProductVersions
shenzhen yipu commercial and trading co.wdr201a wifi extender0, 1.02

References

  • https://mstreet97.github.io/security-research/iot/vulnerability-disclosure/ai-assisted-research/cybersecurity/cve/2026/05/04/Teaching_the_Machine_Where_to_Look.html(technical-description, exploit)
  • https://www.made-in-china.com/showroom/yeapook/#:~:text=Established%20in%202015.%2CDistrict%2C%20Shenzhen%2C%20Guangdong%2C%20China(product)
  • https://www.vulncheck.com/advisories/wdr201a-wifi-extender-os-command-injection-via-makerequest-cgi(third-party-advisory)

Related News (1 articles)

Tier C
VulDB3h ago
CVE-2026-41924 | Yipu WDR201A WiFi Extender up to 1.02 POST Request makeRequest.cgi set_time/StartSniffer os command injection
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-78
PublishedMay 4, 2026
Last enriched2h agov2
Trending Score72
Source articles1
Independent1
Info Completeness7/14
Missing: cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-41922EXP
WDR201A WiFi Extender OS Command Injection via wireless.cgi
Trending: 72
CRITICALCVE-2026-41925
WDR201A WiFi Extender OS Command Injection via adm.cgi (reboot_time)
Trending: 53
CRITICALCVE-2026-41927EXP
WDR201A WiFi Extender Stack-Based Buffer Overflow via firewall.cgi
Trending: 49
CRITICALCVE-2026-41926EXP
WDR201A WiFi Extender OS Command Injection via firewall.cgi
Trending: 49
CRITICALCVE-2026-41923
WDR201A WiFi Extender OS Command Injection via internet.cgi
Trending: 30

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 4, 2026
Discovered by ZDM
May 4, 2026
Actively Exploited
May 4, 2026
Updated: description, affectedVersions, severity, activelyExploited
May 4, 2026

Version History

v2
Last enriched 2h ago
v2Tier C2h ago

Updated severity to CRITICAL, added affected version 1.02, and corrected vendor and product information.

descriptionaffectedVersionsseverityactivelyExploited
via VulDB
v15h ago

Initial creation