Junglewise Threat Intelligence

CVE-2026-19960: Edimax EW-7478APC command injection in formWlbasic

CVE-2026-19960 · Severity: high · CVSS 7.4 · Published 2026-08-16

Technologies: Edimax EW-7478APC. Vendors: Edimax.

Executive brief

The Edimax EW-7478APC is a wireless access point used in small business and enterprise networks. A command injection vulnerability in the web configuration interface allows remote attackers to execute arbitrary system commands without authentication, potentially gaining full control of the device and compromising network security.

Technical details

A command injection vulnerability exists in the formWlbasic function of /goform/formWlbasic on Edimax EW-7478APC firmware version 1.04. The vulnerability is triggered by unsanitized manipulation of the rootAPmac argument, which is passed to a system command without proper validation. An unauthenticated attacker on the network can send a crafted request to inject arbitrary commands that will be executed with device privileges. The exploit has been publicly disclosed and proof-of-concept code is available; however, the vendor has not responded to early disclosure notices or provided a patch.

Affected products

  • Edimax EW-7478APC 1.04

Timeline

  • 2026-08-16: disclosed: Publicly disclosed via VulDB
  • 2026-08-16: advisory: CVE-2026-19960 assigned

References

Related threats