CVE-2026-26213 | themactep thingino-firmware up to firmware-2026-03-16 Password Reset parse_query/parse_post os command injection
A vulnerability classified as critical has been found in themactep thingino-firmware up to firmware-2026-03-16. This issue affects the function parse_query/parse_post of the component Password Reset Handler. Performing a manipulation results in os command injection.
This vulnerability is cataloged as CVE-2026-26213. The attack must originate from the local network. There is no exploit available.
It is recommended to upgrade the affected component.