Junglewise Threat Intelligence

CVE-2025-1316: Edimax IC-7100 IP Camera OS Command Injection Vulnerability

CVE-2025-1316 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-03-19

Vendors: Edimax.

Executive brief

The Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper neutralization of special elements in requests. An unauthenticated remote attacker can exploit this by sending specially crafted requests to achieve arbitrary code execution on the device.

Affected products

  • Edimax IC-7100 firmware all versions
  • Edimax IC-7100

Timeline

  • 2025-03-04: disclosed: Initial CVE publication date
  • 2025-03-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-03-19: exploited: Confirmed as exploited in the wild per CISA KEV entry