Executive brief
A security vulnerability has been identified in the Edimax BR-6478AC V2 wireless router. This flaw allows an attacker to execute unauthorized commands on the device by sending a specially crafted web request. If exploited, an attacker could gain control over the router, potentially leading to network disruptions or unauthorized access to data passing through the device.
Technical details
A command injection vulnerability exists in the Edimax BR-6478AC V2 router running firmware version 1.23. The flaw is located within the 'wiz_5in1_redirect' function of the '/goform/wiz_5in1_redirect' endpoint, which handles POST requests. Specifically, the application fails to properly sanitize the 'newpass' argument before passing it to a system shell. A remote attacker with low privileges can exploit this by sending a crafted POST request to execute arbitrary commands on the underlying operating system. While the vendor was notified, no patch has been released at this time, and public exploit code is reportedly available.
Affected products
- Edimax BR-6478AC V2 1.23
Timeline
- 2026-06-21: disclosed: Vulnerability disclosed via VulDB and NVD
- 2026-06-21: advisory