Junglewise Threat Intelligence

CVE-2026-9378: Edimax BR-6675nD command injection in formHwSet

CVE-2026-9378 · Severity: medium · CVSS 6.3 · Published 2026-05-24

Technologies: Edimax BR-6675nD. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax BR-6675nD wireless router. An attacker can remotely execute unauthorized commands on the device by sending specially crafted web requests. This could lead to a complete takeover of the router, allowing an attacker to intercept network traffic or disrupt internet connectivity.

Technical details

A command injection vulnerability exists in the Edimax BR-6675nD router version 1.12. The flaw is located within the 'formHwSet' function of the '/goform/formHwSet' component, which serves as a POST request handler. By manipulating specific arguments such as 'regDomain', 'ABandregDomain', 'nic0Addr', 'nic1Addr', 'wlanAddr', or 'inicAddr', a remote authenticated attacker can inject and execute arbitrary shell commands. While the attack requires network access and low-level privileges, a public exploit has been released. The vendor has reportedly not responded to disclosure attempts, and no patch is currently available.

Affected products

  • Edimax BR-6675nD 1.12

Timeline

  • 2026-05-24: disclosed: Public disclosure of the vulnerability and exploit.
  • 2026-05-24: advisory: CVE-2026-9378 published.

References

Related threats