Junglewise Threat Intelligence

CVE-2026-13581: Edimax EW-7478APC OS command injection in formStaDrvSetup

CVE-2026-13581 · Severity: medium · CVSS 6.3 · Published 2026-06-29

Technologies: Edimax EW-7478APC. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax EW-7478APC wireless access point. An attacker can remotely inject malicious commands into the device's management interface, potentially leading to unauthorized control of the network hardware. This could allow an attacker to disrupt network services or intercept traffic passing through the device.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Edimax EW-7478APC firmware version 1.04. The flaw is located within the 'formStaDrvSetup' function of the '/goform/formStaDrvSetup' component, which handles POST requests. Specifically, the 'rootAPmac' argument is not properly sanitized before being passed to a system shell. A remote attacker with low privileges can exploit this by sending a specially crafted POST request to execute arbitrary operating system commands. As of the disclosure date, the vendor has not responded to reports, and no patch is currently available.

Affected products

  • Edimax EW-7478APC 1.04

Timeline

  • 2026-06-29: disclosed: Public disclosure of the vulnerability and exploit.
  • 2026-06-29: advisory

References

Related threats