Junglewise Threat Intelligence

CVE-2026-10127: Edimax BR-6478AC command injection in formStaDrvSetup

CVE-2026-10127 · Severity: medium · CVSS 6.3 · Published 2026-05-30

Technologies: Edimax BR-6478AC. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax BR-6478AC wireless router, a device used to provide internet connectivity and networking for homes and small offices. An attacker can remotely send specially crafted commands to the device to take control of its operations. This could lead to unauthorized access to the network, interception of data, or a complete disruption of internet services.

Technical details

An OS command injection vulnerability exists in the Edimax BR-6478AC router version 1.23. The flaw is located within the 'formStaDrvSetup' function of the '/goform/formStaDrvSetup' component, which handles POST requests. By manipulating the 'rootAPmac' argument, a remote attacker with low privileges can inject and execute arbitrary commands on the underlying operating system. The attack vector is network-based and does not require user interaction, though it may require basic authentication (PR:L). Public exploit code is reportedly available.

Affected products

  • Edimax BR-6478AC 1.23

Timeline

  • 2026-05-30: disclosed
  • 2026-05-30: advisory

References

Related threats