Junglewise Threat Intelligence

CVE-2026-9400: Edimax BR-6675nD command injection in formUSBStorage

CVE-2026-9400 · Severity: medium · CVSS 6.3 · Published 2026-05-24

Technologies: Edimax BR-6675nD. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax BR-6675nD wireless router, a device used to provide internet connectivity and network management. An attacker can remotely execute unauthorized commands on the router, potentially leading to a complete takeover of the device, interception of network traffic, or disruption of internet services. This issue is particularly concerning as an exploit has been publicly released and the manufacturer has not yet provided a fix.

Technical details

A command injection vulnerability exists in the Edimax BR-6675nD router version 1.12 within the POST request handler. The flaw is located in the 'formUSBStorage' function of the '/goform/formUSBStorage' endpoint. By manipulating the 'sub_dir' argument in a POST request, a remote attacker with low privileges can inject and execute arbitrary system commands on the underlying operating system. The vulnerability is reachable over the network, and while it requires authentication (PR:L), public exploit code is available. As of the advisory date, the vendor has not responded to disclosure attempts, and no patch is currently available.

Affected products

  • Edimax BR-6675nD 1.12

Timeline

  • 2026-05-24: advisory: Initial disclosure by VulDB and NVD
  • 2026-05-24: disclosed: Exploit published publicly

References

Related threats