Junglewise Threat Intelligence

CVE-2026-9359: Edimax EW-7438RPn command injection in formHwSet

CVE-2026-9359 · Severity: medium · CVSS 6.3 · Published 2026-05-24

Vendors: Edimax.

Executive brief

A vulnerability exists in the Edimax EW-7438RPn Mini, a Wi-Fi extender used to expand wireless network coverage. An attacker can remotely inject malicious commands into the device's management interface, potentially leading to full control over the hardware. This could allow an unauthorized user to disrupt internet connectivity or intercept network traffic passing through the device.

Technical details

A command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.28a within the 'formHwSet' function of the '/goform/formHwSet' component. The vulnerability is triggered by improper neutralization of special elements in several POST request arguments, including 'Anntena', 'Mcs', 'regDomain', and various MAC/IP address fields. A remote attacker with low privileges can exploit this by sending a specially crafted POST request to the device's web interface. Successful exploitation allows for arbitrary command execution on the underlying operating system. As of the disclosure date, the vendor has not provided a patch.

Affected products

  • Edimax EW-7438RPn Mini 1.28a

Timeline

  • 2026-05-24: disclosed: Public disclosure of the vulnerability and exploit details.
  • 2026-05-24: advisory: CVE-2026-9359 published.

References

Related threats