Executive brief
A security vulnerability exists in the Edimax EW-7438RPn Wi-Fi extender that could allow an attacker to take control of the device. By sending a specially crafted web request, a remote user with basic access can execute unauthorized commands on the hardware. This could lead to a complete compromise of the device, potentially allowing attackers to intercept network traffic or disrupt internet connectivity.
Technical details
A command injection vulnerability (CWE-77) exists in the Edimax EW-7438RPn firmware version 1.12. The flaw is located within the 'formAccept' function of the '/goform/formAccep' endpoint, which serves as a POST request handler. An attacker can exploit this by manipulating the 'submit-url' argument to inject and execute arbitrary shell commands. While the attack can be initiated remotely over the network, it requires low-level authentication (PR:L). A public exploit has been disclosed, and the vendor has reportedly not responded to the disclosure, suggesting no official patch is currently available.
Affected products
- Edimax EW-7438RPn 1.12
Timeline
- 2026-05-24: disclosed: Initial public disclosure via VulDB and NVD
- 2026-05-24: advisory