Junglewise Threat Intelligence

CVE-2026-9441: Edimax BR-6478AC command injection in formiNICbasic

CVE-2026-9441 · Severity: medium · CVSS 6.3 · Published 2026-05-25

Technologies: Edimax BR-6478AC. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax BR-6478AC wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can remotely inject malicious commands into the device's management interface, potentially leading to full control over the router. This could allow an unauthorized party to disrupt internet service, intercept network traffic, or use the device as a foothold for further attacks on the local network.

Technical details

A command injection vulnerability exists in the Edimax BR-6478AC router version 1.23 within the POST request handler component. The flaw is located in the 'formiNICbasic' function of the '/goform/formiNICbasic' endpoint. By manipulating the 'rootAPmac' argument in a network request, an attacker with low privileges can execute arbitrary system commands on the underlying operating system. The attack can be carried out remotely over the network. As of the disclosure date, the vendor has not responded to reports, and no official patch is available. Public exploit code has been released.

Affected products

  • Edimax BR-6478AC 1.23

Timeline

  • 2026-05-25: advisory: Initial disclosure by VulDB and NVD
  • 2026-05-25: disclosed: Public exploit released

References

Related threats