Executive brief
A security vulnerability exists in the Edimax BR-6675nD wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can remotely take control of the device by sending a specially crafted request to the Wi-Fi Protected Setup (WPS) configuration page. This could allow an unauthorized user to disrupt internet service, intercept network traffic, or use the device as a foothold for further attacks on the local network.
Technical details
A command injection vulnerability exists in the Edimax BR-6675nD router version 1.12 within the POST request handler for WPS configuration. The flaw is located in the 'formWpsStart' function of the '/goform/formWpsStart' endpoint. Specifically, the 'pinCode' argument is not properly sanitized before being passed to a system shell, allowing an authenticated remote attacker to execute arbitrary OS commands. While the vendor was notified, no patch has been released, and public exploit code is currently available. The attack requires network reachability to the router's management interface and low-level authentication.
Affected products
- Edimax BR-6675nD 1.12
Timeline
- 2026-05-24: disclosed: Initial public disclosure via VulDB and NVD.
- 2026-05-24: advisory