Executive brief
A security vulnerability exists in the Edimax EW-7478APC wireless access point. An attacker can remotely inject malicious commands into the device's management interface, potentially leading to unauthorized control of the network hardware. This could allow an attacker to disrupt network services or intercept traffic passing through the device.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Edimax EW-7478APC firmware version 1.04. The flaw is located within the 'formStaDrvSetup' function of the '/goform/formStaDrvSetup' component, which handles POST requests. Specifically, the 'rootAPmac' argument is not properly sanitized before being passed to a system shell. A remote attacker with low privileges can exploit this by sending a specially crafted POST request to execute arbitrary operating system commands. As of the disclosure date, the vendor has not responded to reports, and no patch is currently available.
Affected products
- Edimax EW-7478APC 1.04
Timeline
- 2026-06-29: disclosed: Public disclosure of the vulnerability and exploit.
- 2026-06-29: advisory