Junglewise Threat Intelligence

CVE-2026-9439: Edimax BR-6675nD command injection in /goform/stainfo

CVE-2026-9439 · Severity: medium · CVSS 6.3 · Published 2026-05-25

Technologies: Edimax BR-6675nD. Vendors: Edimax.

Executive brief

A vulnerability exists in the Edimax BR-6675nD wireless router, a device used to provide internet connectivity and networking for homes and small offices. An attacker can remotely execute unauthorized commands on the router, potentially leading to a complete takeover of the device, interception of network traffic, or disruption of internet services. This issue is particularly concerning as technical details and exploit methods have been made public, and the manufacturer has not yet provided a fix.

Technical details

A command injection vulnerability exists in the Edimax BR-6675nD router running firmware version 1.12. The flaw is located within the 'stainfo' function of the '/goform/stainfo' endpoint, where the 'interface' parameter is improperly neutralized before being passed to a system shell. A remote attacker with low-level privileges can exploit this by sending a specially crafted HTTP request to execute arbitrary OS commands. While the CVSS score indicates a requirement for authentication (PR:L), the exploit is reachable over the network. As of the advisory date, the vendor has not responded to disclosure attempts, and no official patch is available.

Affected products

  • Edimax BR-6675nD 1.12

Timeline

  • 2026-05-25: disclosed: Public disclosure of the vulnerability and exploit details.
  • 2026-05-25: advisory: CVE-2026-9439 published.

References

Related threats