Executive brief
A security vulnerability exists in the Edimax BR-6675nD wireless router. An attacker can remotely execute unauthorized commands on the device by sending specially crafted web requests. This could lead to a complete takeover of the router, allowing an attacker to intercept network traffic or disrupt internet connectivity.
Technical details
A command injection vulnerability exists in the Edimax BR-6675nD router version 1.12. The flaw is located within the 'formHwSet' function of the '/goform/formHwSet' component, which serves as a POST request handler. By manipulating specific arguments such as 'regDomain', 'ABandregDomain', 'nic0Addr', 'nic1Addr', 'wlanAddr', or 'inicAddr', a remote authenticated attacker can inject and execute arbitrary shell commands. While the attack requires network access and low-level privileges, a public exploit has been released. The vendor has reportedly not responded to disclosure attempts, and no patch is currently available.
Affected products
- Edimax BR-6675nD 1.12
Timeline
- 2026-05-24: disclosed: Public disclosure of the vulnerability and exploit.
- 2026-05-24: advisory: CVE-2026-9378 published.