Junglewise Threat Intelligence

CVE-2026-9296: Edimax BR-6428NS command injection in formWlanM

CVE-2026-9296 · Severity: medium · CVSS 6.3 · Published 2026-05-23

Technologies: Edimax BR-6428nS. Vendors: Edimax.

Executive brief

A vulnerability exists in the Edimax BR-6428NS wireless router, a device used to provide internet connectivity in home and small office environments. An attacker can remotely execute unauthorized commands on the router, potentially allowing them to take full control of the device, intercept network traffic, or disrupt internet services. This issue is particularly serious because technical details and exploit methods have been released publicly, and the manufacturer has not yet provided a fix.

Technical details

A command injection vulnerability exists in the Edimax BR-6428NS router version 1.10 within the POST request handler for '/goform/formWlanM'. The issue stems from improper neutralization of special elements (CWE-77/CWE-74) in several parameters, including 'ateFunc', 'ateChan', and 'readE2P', which are passed to a system-level function. A remote attacker with low privileges can exploit this by sending a specially crafted POST request to the affected endpoint. Successful exploitation allows for arbitrary command execution on the underlying operating system. As of the advisory date, the vendor has not responded to the disclosure, and no patch is available.

Affected products

  • Edimax BR-6428NS 1.10

Timeline

  • 2026-05-23: disclosed: Public disclosure of the vulnerability and exploit details.
  • 2026-05-23: advisory: CVE-2026-9296 published.

References

Related threats