Executive brief
A security vulnerability exists in the Edimax BR-6428NS wireless router. This device is commonly used to provide Wi-Fi connectivity in home and small office environments. An attacker could exploit this flaw to take control of the router, potentially leading to unauthorized access to network traffic or a complete disruption of internet services. This issue is particularly concerning as the vendor has not yet provided a fix, and technical details on how to exploit it are publicly available.
Technical details
A command injection vulnerability exists in the Edimax BR-6428NS router version 1.10. The flaw is located within the 'formWlbasic' function of the '/goform/formWlbasic' endpoint, which serves as a POST request handler. By manipulating the 'repeaterSSID' argument, a remote attacker with low privileges can inject and execute arbitrary system commands on the underlying operating system. The attack vector is network-based and does not require user interaction, though it typically requires authentication (PR:L). As of the disclosure date, the vendor has not responded to reports, and no official patch is available. Public exploit code is reportedly available.
Affected products
- Edimax BR-6428NS 1.10
Timeline
- 2026-05-23: disclosed: Public disclosure of the vulnerability and exploit details.
- 2026-05-23: advisory: CVE-2026-9297 published.