AddMac of the file /cgi-bin/wireless.cgi. This manipulation of the argument macAddr causes command injection.
This vulnerability is tracked as CVE-2026-2530. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
Intelligence View
SOCIAL SHARE CARD GENERATOR