Executive brief
The Edimax EW-7478APC wireless access point contains a command injection vulnerability in its web management interface that allows remote attackers to execute arbitrary system commands. An attacker can manipulate the interface parameter in the /goform/stainfo endpoint to inject and execute commands, potentially gaining full control of the device and the network it manages.
Technical details
The vulnerability is a command injection flaw in the stainfo function of the /goform/stainfo endpoint in Edimax EW-7478APC firmware version 1.04. The vulnerable component fails to properly sanitize the interface parameter, allowing an attacker to inject shell metacharacters and arbitrary commands. The attack is remotely accessible with no authentication required. A successful exploit enables arbitrary command execution with the privileges of the web server process, typically allowing full system compromise. No vendor patch is available as the vendor did not respond to early disclosure notifications.
Affected products
- Edimax EW-7478APC 1.04
Timeline
- 2026-08-17: disclosed
- other: Vendor contacted but did not respond