Junglewise Threat Intelligence

CVE-2026-8774: Edimax BR-6228NC command injection in POST Request Handler

CVE-2026-8774 · Severity: medium · CVSS 6.3 · Published 2026-05-18

Vendors: Edimax.

Executive brief

A vulnerability exists in the Edimax BR-6228NC router, a device used to provide wireless networking for homes and small offices. An attacker can remotely execute unauthorized commands on the router by sending a specially crafted web request. This could allow an attacker to take control of the device, disrupt internet connectivity, or monitor network traffic.

Technical details

A command injection vulnerability exists in the Edimax BR-6228NC router running firmware version 1.22. The flaw is located within the 'mp' function of the '/goform/mp' file, which serves as a POST request handler. By manipulating the 'command' argument in a POST request, a remote attacker with low privileges can execute arbitrary system commands on the underlying operating system. The attack vector is network-based and does not require user interaction. As of the disclosure date, the vendor has not responded to reports, and public exploit code is reportedly available.

Affected products

  • Edimax BR-6228NC 1.22

Timeline

  • 2026-05-18: advisory: NVD publication date
  • 2026-05-18: disclosed: Public disclosure of the vulnerability and exploit

References