Junglewise Threat Intelligence

CVE-2026-12807: Edimax BR-6478AC V2 command injection in setWAN

CVE-2026-12807 · Severity: medium · CVSS 6.3 · Published 2026-06-21

Technologies: Edimax BR-6478AC V2. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax BR-6478AC V2 router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to take control of the device by sending specially crafted network requests to the Wide Area Network (WAN) configuration settings. This could lead to unauthorized access to the network, interception of data, or disruption of internet services.

Technical details

A command injection vulnerability exists in the Edimax BR-6478AC V2 router running firmware version 1.23. The flaw is located within the 'setWAN' function of the '/goform/setWAN' endpoint, which handles POST requests. Specifically, the application fails to properly sanitize the 'pppUserName', 'pptpUserName', and 'L2TPUserName' arguments. A remote attacker with low privileges can exploit this by submitting malicious input through these parameters to execute arbitrary system commands on the underlying operating system. While the vendor was notified, no patch has been released, and public exploit code is reportedly available.

Affected products

  • Edimax BR-6478AC V2 1.23

Timeline

  • 2026-06-21: advisory: NVD publication date
  • 2026-06-21: disclosed: Public disclosure of the vulnerability and exploit

References

Related threats