CVE-2026-2548

Severity CVSS v4.0:
MEDIUM
Type:
CWE-74 Injection
Publication date:
16/02/2026
Last modified:
17/02/2026

Description

A flaw has been found in WAYOS FBM-220G 24.10.19. This affects the function sub_40F820 of the file rc. Executing a manipulation of the argument upnp_waniface/upnp_ssdp_interval/upnp_max_age can lead to command injection. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.