Junglewise Threat Intelligence

CVE-2026-10166: Edimax BR-6478AC command injection in formWlbasic

CVE-2026-10166 · Severity: medium · CVSS 6.3 · Published 2026-05-31

Technologies: Edimax BR-6478AC. Vendors: Edimax.

Executive brief

A vulnerability exists in the Edimax BR-6478AC wireless router, a device used to provide internet connectivity and networking for homes and small offices. An attacker can exploit this flaw to take control of the router by injecting malicious commands through its web management interface. This could lead to unauthorized access to network traffic, disruption of internet services, or further attacks on devices connected to the local network.

Technical details

A command injection vulnerability exists in the Edimax BR-6478AC router version 1.23 within the POST request handler for /goform/formWlbasic. The root cause is improper neutralization of special elements in the 'rootAPmac' argument processed by the formWlbasic function. A remote attacker with low privileges (authenticated) can exploit this by sending a specially crafted POST request to execute arbitrary commands on the underlying operating system. The exploit for this vulnerability has been publicly disclosed. At the time of reporting, no official patch has been confirmed.

Affected products

  • Edimax BR-6478AC 1.23

Timeline

  • 2026-05-31: disclosed: Public disclosure of the vulnerability and exploit details.
  • 2026-05-31: advisory: CVE-2026-10166 published.

References

Related threats