Junglewise Threat Intelligence

CVE-2026-9362: Edimax EW-7438RPn command injection in Setting Handler

CVE-2026-9362 · Severity: medium · CVSS 6.3 · Published 2026-05-24

Technologies: Edimax EW-7438RPn. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax EW-7438RPn Wi-Fi extender, a device used to increase the range of wireless networks. An attacker can remotely inject malicious commands into the device's settings handler, potentially allowing them to take control of the hardware. This could lead to unauthorized access to the network, interception of data, or disruption of internet connectivity.

Technical details

A command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.12. The flaw is located within the 'formConnectionSetting' function of the '/goform/formConnectionSetting' endpoint in the Setting Handler component. By manipulating the 'max_Conn' or 'timeOut' arguments, a remote attacker with low privileges can inject and execute arbitrary system commands. The vulnerability is reachable over the network, and while an exploit has been publicly disclosed, the vendor has reportedly not responded to the disclosure.

Affected products

  • Edimax EW-7438RPn 1.12

Timeline

  • 2026-05-24: disclosed: Public disclosure of the vulnerability and exploit.
  • 2026-05-24: advisory: CVE-2026-9362 published.

References

Related threats