Junglewise Threat Intelligence

CVE-2026-13561: Edimax EW-7478APC OS command injection in formiNICbasic

CVE-2026-13561 · Severity: medium · CVSS 6.3 · Published 2026-06-29

Technologies: Edimax EW-7478APC. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax EW-7478APC router that could allow an attacker to take control of the device. By sending a specially crafted web request, an unauthorized user can execute system-level commands. This could lead to a complete compromise of the router, allowing attackers to intercept network traffic or disrupt internet connectivity.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Edimax EW-7478APC router, specifically within the 'formiNICbasic' function of the '/goform/formiNICbasic' endpoint. The vulnerability is triggered by improper neutralization of the 'rootAPmac' argument passed via a POST request. A remote attacker with low privileges can exploit this flaw to execute arbitrary operating system commands on the underlying device. As of the disclosure date, the vendor has not responded to reports, and public exploit code is reportedly available.

Affected products

  • Edimax EW-7478APC 1.04

Timeline

  • 2026-06-29: disclosed: Public disclosure of the vulnerability and exploit.
  • 2026-06-29: advisory: CVE-2026-13561 published.

References

Related threats