CVE-2026-38711
Last modified
CVE-2026-38711 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.upgrade_check interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.upgrade_check interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-38711?
How severe is CVE-2026-38711?
How do I fix CVE-2026-38711?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-38704A command injection vulnerability exists in the WireGuard VP…9.8
- CVE-2026-38707A command injection vulnerability exists in the IPSec VPN fe…9.8
- CVE-2026-38708TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.2…9.8
- CVE-2026-38709TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.2…9.8
- CVE-2026-3871A buffer overflow vulnerability in the UPnP DeletePortMappin…6.5
- CVE-2026-38710TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain…7.2
- CVE-2026-38713TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.2…9.8
- CVE-2026-38714InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 …9.8
- CVE-2026-38715InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 …9.8
- CVE-2026-38716InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 …9.8
- CVE-2026-38717InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 …9.8
- CVE-2026-38718InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 …7.5
Are you affected by CVE-2026-38711?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
