Junglewise Threat Intelligence

CVE-2026-9347: Edimax EW-7438RPn OS command injection in formWizSurvey

CVE-2026-9347 · Severity: medium · CVSS 6.3 · Published 2026-05-24

Technologies: Edimax EW-7438RPn. Vendors: Edimax.

Executive brief

A vulnerability exists in the Edimax EW-7438RPn Wi-Fi extender that allows an attacker to take control of the device. By sending a specially crafted request to the device's web management interface, an attacker can execute unauthorized system commands. This could lead to a complete compromise of the device, allowing an attacker to intercept network traffic or use the device as a foothold for further attacks on the local network.

Technical details

An OS command injection vulnerability exists in the 'webs' binary of Edimax EW-7438RPn firmware up to version 1.31. The vulnerability is located within the 'formWizSurvey' function in the '/goform/formWizSurvey' endpoint. The application fails to properly sanitize the 'ip', 'mask', and 'gateway' POST parameters before passing them to a system shell. A remote attacker with low privileges (authenticated access) can exploit this by submitting backticked commands or shell metacharacters in these fields to achieve arbitrary code execution. As of the advisory date, the vendor has not responded to disclosure attempts and no patch is available.

Affected products

  • Edimax EW-7438RPn up to 1.31

Timeline

  • 2026-05-24: disclosed: Public disclosure of the vulnerability and PoC
  • 2026-05-24: advisory: NVD publication date

References

Related threats