Executive brief
A security vulnerability exists in the Edimax BR-6478AC router, a device used to provide wireless internet connectivity. An attacker can remotely send specially crafted instructions to the router to take control of the device. This could allow an unauthorized person to disrupt internet service, intercept network traffic, or use the router as a foothold to attack other devices on the local network.
Technical details
A command injection vulnerability exists in the Edimax BR-6478AC router version 1.23 within the POST request handler component. Specifically, the 'formAccept' function in the '/goform/formAccept' file fails to properly sanitize the 'submit-url' argument. A remote attacker with low privileges can exploit this by sending a crafted POST request to inject and execute arbitrary shell commands on the underlying operating system. While the vendor was notified, no patch has been released, and public exploit code is reportedly available.
Affected products
- Edimax BR-6478AC 1.23
Timeline
- 2026-05-25: advisory: Initial disclosure by VulDB and NVD
- 2026-05-25: disclosed: Public exploit code made available