Edimax Edimax

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Edimax product.

RSS Feeds for Edimax security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Edimax products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Edimax Sorted by Most Security Vulnerabilities since 2018

Edimax Ew 7438rpn24 vulnerabilities

Edimax Ew 7478apc14 vulnerabilities

Edimax Br 6675nd12 vulnerabilities

Edimax Br 6478ac Firmware12 vulnerabilities

Edimax Br 6428ns Firmware11 vulnerabilities

Edimax Br 6478ac V3 Firmware8 vulnerabilities

Edimax Re11s Firmware8 vulnerabilities

Edimax Br 6208ac Firmware7 vulnerabilities

Edimax Br 6476ac Firmware5 vulnerabilities

Edimax Br 6478ac V25 vulnerabilities

Edimax Gs 5008pl5 vulnerabilities

Edimax Br 6288acl Firmware3 vulnerabilities

Edimax Ew 7438rpn Mini V22 vulnerabilities

Edimax Br 6104k1 vulnerability

Edimax Cv 7428ns Firmware1 vulnerability

Edimax Br 6228nc1 vulnerability

Edimax Ic 7100 Firmware1 vulnerability

Known Exploited Edimax Vulnerabilities

The following Edimax vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Edimax IC-7100 IP Camera OS Command Injection Vulnerability Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2025-1316 Exploit Probability: 73.0%
March 19, 2025

The vulnerability CVE-2025-1316: Edimax IC-7100 IP Camera OS Command Injection Vulnerability is in the top 1% of the currently known exploitable vulnerabilities.

By the Year

In 2026 there have been 91 vulnerabilities in Edimax with an average score of 7.5 out of ten. Last year, in 2025 Edimax had 30 security vulnerabilities published. That is, 61 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.05




Year Vulnerabilities Average Score
2026 91 7.53
2025 30 7.58
2024 1 9.80
2023 5 9.40

It may take a day or so for new Edimax vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Edimax Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-19963 Aug 16, 2026
Edimax EW-7478APC 1.04 Remote cmd injection via /goform/stainfo A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function stainfo of the file /goform/stainfo. The manipulation of the argument interface leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7478apc
CVE-2026-19962 Aug 16, 2026
Command Injection via setWAN in Edimax EW-7478APC 1.04 (pppUserName/v1.04) A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipulation of the argument pppUserName/pptpUserName/L2TPUserName can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7478apc
CVE-2026-19961 Aug 16, 2026
Edimax EW-7478APC 1.04 Buffer Overflow in formWlSiteSurvey (Remote) A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7478apc
CVE-2026-19960 Aug 16, 2026
Command Injection in Edimax EW-7478APC 1.04, formWlbasic rootAPmac exploit A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such manipulation of the argument rootAPmac leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7478apc
CVE-2026-19959 Aug 16, 2026
Edimax EW-7478APC 1.04 Remote Stack Buffer Overflow via pppUserName A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7478apc
CVE-2026-13583 Jun 29, 2026
Edimax EW-7478APC 1.04 Buffer Overflow via /goform/formUSBFolder POST A vulnerability has been found in Edimax EW-7478APC 1.04. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. Such manipulation of the argument ShareName/SelectName leads to buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7478apc
CVE-2026-13582 Jun 29, 2026
Edimax EW-7478APC 1.04 Buffer Overflow via formUSBAccount (POST Handler) A flaw has been found in Edimax EW-7478APC 1.04. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. This manipulation of the argument UserName/Password causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7478apc
CVE-2026-13581 Jun 29, 2026
Edimax EW-7478APC 1.04 - OS-Command Injection via rootAPmac POST A vulnerability was detected in Edimax EW-7478APC 1.04. This vulnerability affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. The manipulation of the argument rootAPmac results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7478apc
CVE-2026-13580 Jun 29, 2026
Buffer Overflow in Edimax EW-7478APC 1.04 /goform/formQoS (POST) A security vulnerability has been detected in Edimax EW-7478APC 1.04. This affects the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7478apc
CVE-2026-13564 Jun 29, 2026
Stack-based BO in Edimax EW-7478APC 1.04 POST Handler A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. Performing a manipulation of the argument pppUserName results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7478apc
CVE-2026-13563 Jun 29, 2026
Edimax EW-7478APC 1.04: Remote Stack BOF via L2TPUserName A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such manipulation of the argument L2TPUserName leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7478apc
CVE-2026-13562 Jun 29, 2026
Buffer overflow via formiNICSiteSurvey in Edimax EW-7478APC 1.04 POST A flaw has been found in Edimax EW-7478APC 1.04. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. This manipulation of the argument selSSID causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7478apc
CVE-2026-13561 Jun 29, 2026
Edimax EW-7478APC 1.04: POST /goform/formiNICbasic rootAPmac OS Cmd Injection A vulnerability was detected in Edimax EW-7478APC 1.04. The impacted element is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. The manipulation of the argument rootAPmac results in os command injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7478apc
CVE-2026-13560 Jun 29, 2026
Edimax EW-7478APC 1.04 OS Command Injection via formAccept A security vulnerability has been detected in Edimax EW-7478APC 1.04. The affected element is the function formAccept of the file /goform/formAccept of the component POST Request Handler. The manipulation of the argument submit-url leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7478apc
CVE-2026-12810 Jun 21, 2026
Edimax BR6478AC V2 1.23 CMD Injection via /goform/mp A security flaw has been discovered in Edimax BR-6478AC V2 1.23. Affected by this vulnerability is the function mp of the file /goform/mp of the component POST Request Handler. Performing a manipulation of the argument command results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6478ac V2
CVE-2026-12809 Jun 21, 2026
Edimax BR-6478AC V2 1.23 Command Injection via wiz_5in1_redirect A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the component POST Request Handler. Such manipulation of the argument newpass leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6478ac V2
CVE-2026-12808 Jun 21, 2026
Edimax BR-6478AC V2 1.23 Command Injection via /goform/stainfo A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainfo of the component POST Request Handler. This manipulation of the argument interface causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6478ac V2
CVE-2026-12807 Jun 21, 2026
Command Injection in Edimax BR-6478AC V2 1.23 setWAN POST Handler A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Handler. The manipulation of the argument pppUserName/pptpUserName/L2TPUserName results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6478ac V2
CVE-2026-12806 Jun 21, 2026
Edimax BR-6478AC V2 1.23 buffer overflow in formWlSiteSurvey via selSSID A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6478ac V2
CVE-2026-10166 May 31, 2026
Remote Cmd Injection in Edimax BR-6478AC 1.23 formWlbasic rootAPmac A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. This manipulation of the argument rootAPmac causes command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Br 6478ac Firmware
CVE-2026-10165 May 31, 2026
Stack Buffer Overflow in Edimax BR-6478AC 1.23 POST Handler A vulnerability was identified in Edimax BR-6478AC 1.23. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manipulation of the argument pppUserName leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and might be used.
Br 6478ac Firmware
CVE-2026-10164 May 31, 2026
Edimax BR-6478AC 1.23 remote USB Folder buffer overflow A vulnerability was found in Edimax BR-6478AC 1.23. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. The manipulation of the argument ShareName/SelectName results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
Br 6478ac Firmware
CVE-2026-10163 May 31, 2026
Edimax BR-6478AC 1.23 POST Request Handler Buffer Overflow A vulnerability has been found in Edimax BR-6478AC 1.23. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. The manipulation of the argument UserName/Password leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Br 6478ac Firmware
CVE-2026-10127 May 30, 2026
Edimax BR-6478AC 1.23 cmd injection via formStaDrvSetup A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. This manipulation of the argument rootAPmac causes command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Br 6478ac Firmware
CVE-2026-10126 May 30, 2026
Buffer Overflow in Edimax BR-6478AC 1.23 FormQoS via POST A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID results in buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Br 6478ac Firmware
CVE-2026-10125 May 30, 2026
Stack Buffer Overflow in Edimax BR-6478AC 1.23 formPPPoESetup via pppUserName A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. The manipulation of the argument pppUserName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used.
Br 6478ac Firmware
CVE-2026-9482 May 25, 2026
Edimax EW-7438RPn 1.31 Remote Stack Overflow via formSDHCP A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the function formSDHCP of the file /goform/formSDHCP. Such manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7438rpn
CVE-2026-9481 May 25, 2026
Stack-based Buffer Overflow in Edimax EW-7438RPn 1.31 (formStats) A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formStats of the file /goform/formStats. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7438rpn
CVE-2026-9480 May 25, 2026
Edimax EW-7438RPn 1.31 Remote SB-Overflow via formrefresh (/goform/formrefresh) A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of the argument submit-url results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7438rpn
CVE-2026-9479 May 25, 2026
Edimax EW-7438RPn 1.31 Stack Buffer Overflow in formLogout (submit-url) A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of the file /goform/formLogout. The manipulation of the argument submit-url leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7438rpn
CVE-2026-9463 May 25, 2026
Edimax EW-7438RPn 1.31 Stack Buffer Overflow in /goform/formLicence Submit-URL A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the function formLicence of the file /goform/formLicence. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7438rpn
CVE-2026-9462 May 25, 2026
Edimax EW-7438RPn 1.31 Stack-Based Buffer Overflow in formWpsProxyEnable A vulnerability was detected in Edimax EW-7438RPn 1.31. Affected by this vulnerability is the function formWpsProxyEnable of the file /goform/formWpsProxyEnable. The manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7438rpn
CVE-2026-9461 May 25, 2026
Edimax EW-7438RPn 1.31 Remote Stack Buffer Overflow in formRadius A security vulnerability has been detected in Edimax EW-7438RPn 1.31. Affected is the function formRadius of the file /goform/formRadius. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7438rpn
CVE-2026-9460 May 25, 2026
Edimax EW-7438RPn 1.31 remote stack overflow via formAccept A weakness has been identified in Edimax EW-7438RPn 1.31. This impacts the function formAccept of the file /goform/formAccept. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7438rpn
CVE-2026-9459 May 25, 2026
Edimax EW-7438RPn 1.31: formConnectionSetting BufOverflow Remote Exploit A security flaw has been discovered in Edimax EW-7438RPn 1.31. This affects the function formConnectionSetting of the file /goform/formConnectionSetting. Performing a manipulation of the argument max_Conn/timeOut results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7438rpn
CVE-2026-9443 May 25, 2026
Edimax BR-6478AC 1.23 POST Handler Buffer Overflow (L2TPUserName) A security vulnerability has been detected in Edimax BR-6478AC 1.23. This vulnerability affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. The manipulation of the argument L2TPUserName leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6478ac Firmware
CVE-2026-9442 May 25, 2026
Edimax BR-6478AC 1.23 Buffer Overflow in formiNICSiteSurvey (selSSID) A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. Executing a manipulation of the argument selSSID can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6478ac Firmware
CVE-2026-9441 May 25, 2026
Command Injection in Edimax BR-6478AC 1.23 POST Handler A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. Performing a manipulation of the argument rootAPmac results in command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6478ac Firmware
CVE-2026-9440 May 25, 2026
Edimax BR-6478AC 1.23: Remote Cmd Injection via formAccept A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of the file /goform/formAccept of the component POST Request Handler. Such manipulation of the argument submit-url leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6478ac Firmware
CVE-2026-9439 May 25, 2026
Edimax BR-6675nD 1.12 Command Injection via /goform/stainfo (stainfo func) A vulnerability was determined in Edimax BR-6675nD 1.12. Affected is the function stainfo of the file /goform/stainfo. This manipulation of the argument interface causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6675nd
CVE-2026-9427 May 25, 2026
Edimax EW-7438RPn 1.31 buffer overflow in webs formWlSiteSurvey A flaw has been found in Edimax EW-7438RPn 1.31. This impacts the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component webs. This manipulation of the argument selSSID/submit-url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7438rpn
CVE-2026-9426 May 25, 2026
Stack Overflow in Edimax EW-7438RPn 1.31 formHwSet (remote) A vulnerability was detected in Edimax EW-7438RPn 1.31. This affects the function formHwSet of the file /goform/formHwSet. The manipulation of the argument Anntena/Mcs/regDomain/nic0Addr/nic1Addr/wlanAddr/wanAddr/wlanSSID/wlanChan/initgain/txcck/txofdm/submit-url results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7438rpn
CVE-2026-9425 May 25, 2026
Edimax EW-7438RPn 1.31 Buffer Overflow via formWlanMP A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The impacted element is the function formWlanMP of the file /goform/formWlanMP. The manipulation of the argument ateFunc/ateGain/ateTxCount/ateChan/ateRate/ateMacID/e2pTxPower1/e2pTxPower2/e2pTxPower3/e2pTxPower4/e2pTxPower5/e2pTxPower6/e2pTxPower7/e2pTx2Power1/e2pTx2Power2/e2pTx2Power3/e2pTx2Power4/e2pTx2Power5/e2pTx2Power6/e2pTx2Power7/ateTxFreqOffset/ateMode/ateBW/ateAntenna/e2pTxFreqOffset/e2pTxPwDeltaB/e2pTxPwDeltaG/e2pTxPwDeltaMix/e2pTxPwDeltaN/readE2P leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7438rpn
CVE-2026-9424 May 25, 2026
OS Command Injection in Edimax EW-7438RPn 1.31 (formWlanMP) A weakness has been identified in Edimax EW-7438RPn 1.31. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component Content-Type Handler. Executing a manipulation of the argument ateFunc/ateGain/ateTxCount/ateChan/ateRate/ateMacID/e2pTxPower1/e2pTxPower2/e2pTxPower3/e2pTxPower4/e2pTxPower5/e2pTxPower6/e2pTxPower7/e2pTx2Power1/e2pTx2Power2/e2pTx2Power3/e2pTx2Power4/e2pTx2Power5/e2pTx2Power6/e2pTx2Power7/ateTxFreqOffset/ateMode/ateBW/ateAntenna/e2pTxFreqOffset/e2pTxPwDeltaB/e2pTxPwDeltaG/e2pTxPwDeltaMix/e2pTxPwDeltaN/readE2P can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Ew 7438rpn
CVE-2026-9423 May 25, 2026
Edimax BR-6675nD 1.12 cmd injection via /goform/mp POST handler A security flaw has been discovered in Edimax BR-6675nD 1.12. Impacted is the function mp of the file /goform/mp of the component POST Request Handler. Performing a manipulation of the argument command results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6675nd
CVE-2026-9403 May 24, 2026
Edimax BR-6675nD 1.12 formWlSiteSurvey Buffer Overflow Remote A vulnerability was determined in Edimax BR-6675nD 1.12. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. This manipulation of the argument selSSID causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6675nd
CVE-2026-9402 May 24, 2026
Command injection in Edimax BR-6675nD 1.12 formWlanMP POST handler A vulnerability was found in Edimax BR-6675nD 1.12. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component POST Request Handler. The manipulation of the argument ateFunc/ateGain/ateRate/ateChan/ateTxCount/e2pTx2Power1/e2pTx2Power2/e2pTx2Power3/e2pTx2Power4/e2pTx2Power5/e2pTx2Power6/e2pTx2Power7/e2pTxPower1/e2pTxPower2/e2pTxPower3/e2pTxPower4/e2pTxPower5/e2pTxPower6/e2pTxPower7/ateTxFreqOffset/ateMode/ateMacID/ateBW/ateAntenna/e2pTxFreqOffset/e2pTxPwDeltaB/e2pTxPwDeltaG/e2pTxPwDeltaMix/readE2P/e2pTxPwDeltaN results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6675nd
CVE-2026-9401 May 24, 2026
Edimax BR-6675nD 1.12 /goform/formWanTcpipSetup Buffer Overflow via pppUserName A vulnerability has been found in Edimax BR-6675nD 1.12. Impacted is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. The manipulation of the argument pppUserName leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6675nd
CVE-2026-9400 May 24, 2026
Command Injection via formUSBStorage on Edimax BR-6675nD 1.12 A flaw has been found in Edimax BR-6675nD 1.12. This issue affects the function formUSBStorage of the file /goform/formUSBStorage of the component POST Request Handler. Executing a manipulation of the argument sub_dir can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6675nd
CVE-2026-9399 May 24, 2026
Edimax BR-6675nD 1.12 Buffer Overrun via formsetPPPoE (pppUserName) A vulnerability was detected in Edimax BR-6675nD 1.12. This vulnerability affects the function formsetPPPoE of the file /goform/formsetPPPoE of the component POST Request Handler. Performing a manipulation of the argument pppUserName results in buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Br 6675nd
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.