Executive brief
The Edimax BR-6428nS V3 router, commonly used for home and small office networking, contains a security flaw in its wireless configuration settings. An authorized user on the network can exploit this to run unauthorized commands on the router's internal system. This could lead to a complete takeover of the device, allowing an attacker to monitor internet traffic, change network settings, or disable the device entirely.
Technical details
A command injection vulnerability (CWE-77) exists in the web-based management interface of the Edimax BR-6428nS V3 router running firmware version 1.15. The flaw is located within the WLAN configuration functionality, where the application fails to sufficiently validate user-supplied input before passing it to a system shell. An authenticated attacker with network access can submit crafted input containing shell metacharacters to vulnerable parameters. Successful exploitation allows for arbitrary command execution on the underlying operating system with the privileges of the web service, potentially leading to full device compromise.
Affected products
- Edimax BR-6428nS V3 1.15
Timeline
- 2026-05-09: disclosed: Initial disclosure date reported by researcher
- 2026-05-11: advisory: CVE published to NVD