CVE-2026-38709
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
30/07/2026
Last modified:
31/07/2026
Description
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



