Junglewise Threat Intelligence

CVE-2026-12808: Edimax BR-6478AC V2 command injection in stainfo POST handler

CVE-2026-12808 · Severity: medium · CVSS 6.3 · Published 2026-06-21

Technologies: Edimax BR-6478AC V2. Vendors: Edimax.

Executive brief

A security vulnerability has been identified in the Edimax BR-6478AC V2 wireless router. This device is commonly used to provide internet connectivity and manage local network traffic for homes and small offices. An attacker could exploit this flaw to take control of the router's operating system, potentially leading to unauthorized access to network traffic or a complete disruption of internet services.

Technical details

A command injection vulnerability exists in the Edimax BR-6478AC V2 router running firmware version 1.23. The flaw is located within the 'stainfo' function of the '/goform/stainfo' component, which handles POST requests. By manipulating the 'interface' argument, a remote attacker with low privileges can inject and execute arbitrary system commands on the underlying operating system. The attack vector is network-based and does not require user interaction, though it may require basic authentication (PR:L). As of the advisory date, the vendor has not responded to disclosure attempts, and no official patch is currently available.

Affected products

  • Edimax BR-6478AC V2 1.23

Timeline

  • 2026-06-21: disclosed: Vulnerability disclosed and added to NVD/VulDB

References

Related threats