NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.
https://github.com/yanggao017/vuln/blob/main/NETGEAR/RAX5/CI_5_apcli_cancel_wps/README.md