Junglewise Threat Intelligence

CVE-2026-13560: Edimax EW-7478APC OS command injection in formAccept

CVE-2026-13560 · Severity: medium · CVSS 6.3 · Published 2026-06-29

Technologies: Edimax EW-7478APC. Vendors: Edimax.

Executive brief

A security vulnerability has been identified in the Edimax EW-7478APC router. This device is used to provide wireless networking and internet connectivity for homes and small offices. An attacker could exploit this flaw to take control of the device, potentially leading to network disruptions or unauthorized access to the router's settings.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Edimax EW-7478APC router, specifically within the 'formAccept' function of the '/goform/formAccept' component. The vulnerability is triggered by improper neutralization of the 'submit-url' argument during a POST request. A remote attacker with low privileges can exploit this to execute arbitrary commands on the underlying operating system. The exploit has been disclosed publicly, and as of the advisory date, the vendor has not responded to disclosure attempts or provided a patch.

Affected products

  • Edimax EW-7478APC 1.04

Timeline

  • 2026-06-29: advisory: Initial disclosure by VulDB and NVD
  • 2026-06-29: disclosed: Public exploit disclosed

References

Related threats