Junglewise Threat Intelligence

CVE-2026-9402: Edimax BR-6675nD command injection in formWlanMP

CVE-2026-9402 · Severity: medium · CVSS 6.3 · Published 2026-05-24

Technologies: Edimax BR-6675nD. Vendors: Edimax.

Executive brief

A vulnerability exists in the Edimax BR-6675nD wireless router that allows an attacker to take control of the device. By sending a specially crafted web request to the router's management interface, an unauthorized user could execute system commands. This could lead to a complete compromise of the network traffic passing through the device or a total service outage.

Technical details

A command injection vulnerability exists in the Edimax BR-6675nD router version 1.12. The flaw is located within the 'formWlanMP' function of the '/goform/formWlanMP' endpoint, which serves as a POST request handler. Multiple parameters, including 'ateFunc', 'ateGain', and 'ateRate', fail to properly neutralize special elements before they are used in system commands. A remote attacker with low privileges can exploit this by sending a malicious POST request to execute arbitrary commands on the underlying operating system. As of the disclosure date, the vendor has not provided a patch.

Affected products

  • Edimax BR-6675nD 1.12

Timeline

  • 2026-05-24: disclosed: Vulnerability disclosed via VulDB and NVD.
  • 2026-05-24: advisory

References

Related threats