What is CVE-2026-38711?
CVE-2026-38711 is a command injection vulnerability found in the `system.upgrade_check` interface of several router models including TR1200, TR3000, WR300, WR1200, WR1300, WR1500, WR3000, WR3600, and WR6500. This flaw allows remote attackers to execute arbitrary commands on the affected device. Immediate firmware updates are recommended.
Azərbaycanca: CVE-2026-38711 bir neçə TR1200, TR3000, WR300, WR1200, WR1300, WR1500, WR3000, WR3600 və WR6500 router modellərinin `system.upgrade_check` interfeysində aşkarlanmış command injection zəifliyidir. Bu boşluq uzaqdan hücum edən şəxslərə təsirlənmiş cihazda ixtiyari əmrlər icra etməyə imkan verir. Cihazları dərhal ən son proqram təminatına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which devices are affected by CVE-2026-38711?
This vulnerability affects the TR1200, TR3000, WR300, WR1200, WR1300, WR1500, WR3000, WR3600, and WR6500 router models.
What should I do to protect against CVE-2026-38711?
It is recommended to immediately update your devices to the latest firmware.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.