Junglewise Threat Intelligence

CVE-2026-9361: Edimax EW-7438RPn command injection in formAccept

CVE-2026-9361 · Severity: medium · CVSS 6.3 · Published 2026-05-24

Technologies: Edimax EW-7438RPn. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax EW-7438RPn Wi-Fi extender that could allow an attacker to take control of the device. By sending a specially crafted web request, a remote user with basic access can execute unauthorized commands on the hardware. This could lead to a complete compromise of the device, potentially allowing attackers to intercept network traffic or disrupt internet connectivity.

Technical details

A command injection vulnerability (CWE-77) exists in the Edimax EW-7438RPn firmware version 1.12. The flaw is located within the 'formAccept' function of the '/goform/formAccep' endpoint, which serves as a POST request handler. An attacker can exploit this by manipulating the 'submit-url' argument to inject and execute arbitrary shell commands. While the attack can be initiated remotely over the network, it requires low-level authentication (PR:L). A public exploit has been disclosed, and the vendor has reportedly not responded to the disclosure, suggesting no official patch is currently available.

Affected products

  • Edimax EW-7438RPn 1.12

Timeline

  • 2026-05-24: disclosed: Initial public disclosure via VulDB and NVD
  • 2026-05-24: advisory

References

Related threats