Executive brief
The Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper neutralization of special elements in requests. An unauthenticated remote attacker can exploit this by sending specially crafted requests to achieve arbitrary code execution on the device.
Affected products
- Edimax IC-7100 firmware all versions
- Edimax IC-7100
Timeline
- 2025-03-04: disclosed: Initial CVE publication date
- 2025-03-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-03-19: exploited: Confirmed as exploited in the wild per CISA KEV entry