Junglewise Threat Intelligence

CVE-2026-19962: Edimax EW-7478APC command injection in setWAN

CVE-2026-19962 · Severity: high · CVSS 7.4 · Published 2026-08-17

Technologies: Edimax EW-7478APC. Vendors: Edimax.

Executive brief

The Edimax EW-7478APC is a wireless access point used to extend network coverage in homes and offices. A flaw in the device's web configuration interface allows remote attackers to inject arbitrary commands by manipulating username parameters (pppUserName, pptpUserName, or L2TPUserName) in the setWAN function. An attacker could gain complete control of the device, redirect network traffic, or use it as a foothold to compromise connected networks.

Technical details

The vulnerability is a command injection flaw in the setWAN function of the /goform/setWAN endpoint on the Edimax EW-7478APC firmware version 1.04. The function fails to properly sanitize username input parameters (pppUserName, pptpUserName, L2TPUserName), allowing an attacker to embed shell commands that are executed with device privileges. The attack is unauthenticated and remotely exploitable over the network. A successful exploit grants an attacker arbitrary code execution on the device. The vendor was notified but has not released a patch.

Affected products

  • Edimax EW-7478APC 1.04

Timeline

  • 2026-08-17: disclosed

References

Related threats