Executive brief
The Edimax EW-7438RPn is a Wi-Fi extender used to increase wireless network coverage. A security flaw in its web management interface allows an attacker to take control of the device by sending a specially crafted request. This could lead to unauthorized access to the network, interception of traffic, or a complete disruption of the device's functionality.
Technical details
An OS command injection vulnerability exists in the 'webs' binary of the Edimax EW-7438RPn Wi-Fi extender (firmware versions up to 1.31). The flaw is located within the 'formWpsStart' function in the '/goform/formWpsStart' endpoint. The application fails to properly sanitize the 'pinCode' POST parameter before passing it to a system shell. A remote attacker with low privileges (authenticated access) can exploit this by injecting shell commands (e.g., using backticks) into the pinCode field. Successful exploitation allows for arbitrary code execution on the underlying operating system, such as starting a telnet daemon for persistent remote access. As of the advisory date, the vendor has not responded to disclosure attempts.
Affected products
- Edimax EW-7438RPn up to 1.31
Timeline
- 2026-05-23: disclosed: Initial public disclosure via VulDB and GitHub PoC
- 2026-05-23: advisory: CVE-2026-9343 published