Junglewise Threat Intelligence

CVE-2026-12810: Edimax BR-6478AC V2 command injection in POST Request Handler

CVE-2026-12810 · Severity: medium · CVSS 6.3 · Published 2026-06-21

Technologies: Edimax BR-6478AC V2. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax BR-6478AC V2 wireless router. An attacker can exploit this flaw to execute unauthorized commands on the device, potentially leading to full control over the router, interception of network traffic, or disruption of internet services. This issue is particularly concerning as a public exploit is already available.

Technical details

A command injection vulnerability exists in the Edimax BR-6478AC V2 router, specifically within the 'mp' function of the '/goform/mp' file. The vulnerability is located in the POST Request Handler component, where the 'command' argument is improperly neutralized before being executed. A remote attacker with low privileges can exploit this by sending a specially crafted POST request to execute arbitrary system commands. While the vendor was notified, no patch has been released, and a public exploit is currently available.

Affected products

  • Edimax BR-6478AC V2 1.23

Timeline

  • 2026-06-21: disclosed: Vulnerability disclosed via VulDB and NVD.
  • 2026-06-21: advisory

References

Related threats