What is CVE-2026-38709?
A command injection vulnerability was discovered in the `net.set_wan` interface of several Redrouter router models, including TR1200, TR3000, and WR300. This flaw allows attackers to execute arbitrary commands on the affected device. It is recommended to disable remote management interfaces until a security patch is released by the vendor.
Azərbaycanca: Bu boşluq Redrouter-in müxtəlif router modellərində (TR1200, TR3000, WR300 və s.) `net.set_wan` interfeysində aşkarlanmış command injection zəifliyidir. Təcavüzkar bu zəiflik vasitəsilə cihazda ixtiyari əmrlər icra edə bilər. İstehsalçı tərəfindən təhlükəsizlik yeniləməsi yayımlanana qədər cihazların uzaqdan idarəetmə interfeyslərinin deaktiv edilməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which Redrouter router models are affected by CVE-2026-38709?
This vulnerability affects various Redrouter router models such as TR1200, TR3000, and WR300.
What is the recommended mitigation for CVE-2026-38709 until a security patch is released?
It is recommended to disable remote management interfaces on the devices.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.