Executive brief
A vulnerability exists in the Edimax BR-6428NS wireless router that allows an attacker to execute unauthorized commands. By sending a specially crafted web request to the device's configuration interface, a remote user could gain control over the router's operations. This could lead to service disruptions or unauthorized access to the local network.
Technical details
A command injection vulnerability (CWE-77) exists in the Edimax BR-6428NS router version 1.10. The flaw is located within the formStaDrvSetup function in the /goform/formStaDrvSetup component, which handles POST requests. An attacker can trigger this vulnerability by manipulating the 'stadrv_ssid' argument. While the attack requires network reachability and low-level privileges (PR:L), it allows for remote command execution on the underlying operating system. As of the disclosure date, the vendor has not responded to reports, and no official patch is available. Public exploit code is reportedly available.
Affected products
- Edimax BR-6428NS 1.10
Timeline
- 2026-05-18: disclosed: Initial public disclosure via VulDB and NVD