OS Command Injection in WEX-G300 and WSR-300HP - CVE-2026-86530
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation. A remote administrator can send a specially crafted HTTP request and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
WSR-300HP
How to mitigate CVE-2026-86530
WSR-300HP - update to 2.55