Junglewise Threat Intelligence

CVE-2026-9423: Edimax BR-6675nD command injection in POST Request Handler

CVE-2026-9423 · Severity: medium · CVSS 4.7 · Published 2026-05-25

Technologies: Edimax BR-6675nD. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax BR-6675nD wireless router. An attacker with administrative access can remotely execute unauthorized commands on the device. This could lead to a complete takeover of the router, potentially allowing the attacker to monitor network traffic or disrupt internet connectivity.

Technical details

A command injection vulnerability exists in the Edimax BR-6675nD router version 1.12. The flaw is located within the 'mp' function of the '/goform/mp' file, which serves as a POST request handler. By manipulating the 'command' argument in a POST request, a remote attacker with high privileges (PR:H) can execute arbitrary commands on the underlying operating system. While the attack requires authentication, a public exploit has been released, increasing the risk of exploitation. The vendor has reportedly not responded to disclosure attempts, and no patch is currently available.

Affected products

  • Edimax BR-6675nD 1.12

Timeline

  • 2026-05-25: advisory: Vulnerability published on NVD
  • 2026-05-25: disclosed: Public exploit released

References

Related threats