CVE-2026-30704CRITICAL 9.1EPSS p22.2%

CVE-2026-30704CVE-2026-30704

Description

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS0.31% probability of exploitation · percentile 22.2% · 2026-06-19T12:03:05Z
Published2026-03-18
Last modified2026-03-19

Underlying weaknesses· 1

CWE-912

References

  1. https://mstreet97.github.io/security-research/iot/vulnerability-disclosure/cybersecurity/cve/2026/02/18/From-Blackbox-to-Whitebox-Multiple-CVEs-in-a-Consumer-WiFi-Extender.html
  2. https://www.made-in-china.com/showroom/yeapook/#:~:text=Established%20in%202015.%2CDistrict%2C%20Shenzhen%2C%20Guangdong%2C%20China

1

TypeTargetConfidenceTier
WeaknessHidden Functionalitycwe-9120%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-30702
CVE
CVE-2026-30703
CVE
CVE-2026-30701
CVE
CVE-2026-0407
CVE
CVE-2026-0408
CVE
CVE-2026-36802
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.