Vendor
Edimax vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 80 vulnerabilities in Edimax: 1 in the last 7 days and 17 in the last 90 days, 3 of them critical and 1 exploited in the wild. The most recent, CVE-2026-96892, was published on 24 September 2026. 6 technologies have a page of their own.
- Last 7 days
- 1
- Last 90 days
- 17
- Critical, all time
- 3
- Exploited in the wild
- 1
About Edimax
A manufacturer of networking solutions, including routers, switches, and network cameras.
Edimax technologies
Latest Edimax vulnerabilities
- CVE-2026-96892: Edimax BR-6428nC open redirect in websRedirect handlermediumCVSS 4.3EPSS 0.3%
- CVE-2026-82703: Edimax BR-6214K OS command injection in ping endpointmediumCVSS 6.6EPSS 2.9%
- CVE-2026-82702: Edimax BR-6214K OS command injection in asp_WlanMPmediumCVSS 6.6EPSS 2.9%
- CVE-2026-19963: Edimax EW-7478APC command injection in stainfohighCVSS 7.4EPSS 2.0%
- CVE-2026-19962: Edimax EW-7478APC command injection in setWANhighCVSS 7.4EPSS 2.0%
- CVE-2026-19961: Edimax EW-7478APC buffer overflow in wireless site surveycriticalCVSS 9.9EPSS 0.8%
- CVE-2026-19960: Edimax EW-7478APC command injection in formWlbasichighCVSS 7.4EPSS 2.0%
- CVE-2026-19959: Edimax EW-7478APC stack buffer overflow in WAN configurationcriticalCVSS 9.9EPSS 0.8%
- CVE-2026-13583: Edimax EW-7478APC buffer overflow in formUSBFolderhighCVSS 8.8
- CVE-2026-13582: Edimax EW-7478APC buffer overflow in formUSBAccounthighCVSS 8.8
- CVE-2026-13581: Edimax EW-7478APC OS command injection in formStaDrvSetupmediumCVSS 6.3
- CVE-2026-13580: Edimax EW-7478APC buffer overflow in formQoS POST handlerhighCVSS 8.8
- CVE-2026-13564: Edimax EW-7478APC stack overflow in formPPPoESetuphighCVSS 8.8
- CVE-2026-13563: Edimax EW-7478APC stack buffer overflow in formL2TPSetuphighCVSS 8.8
- CVE-2026-13562: Edimax EW-7478APC buffer overflow in formiNICSiteSurveyhighCVSS 8.8
- CVE-2026-13561: Edimax EW-7478APC OS command injection in formiNICbasicmediumCVSS 6.3
- CVE-2026-13560: Edimax EW-7478APC OS command injection in formAcceptmediumCVSS 6.3
- CVE-2026-12810: Edimax BR-6478AC V2 command injection in POST Request HandlermediumCVSS 6.3
- CVE-2026-12809: Edimax BR-6478AC V2 command injection in wiz_5in1_redirectmediumCVSS 6.3
- CVE-2026-12808: Edimax BR-6478AC V2 command injection in stainfo POST handlermediumCVSS 6.3
- CVE-2026-12807: Edimax BR-6478AC V2 command injection in setWANmediumCVSS 6.3
- CVE-2026-12806: Edimax BR-6478AC V2 buffer overflow in formWlSiteSurveyhighCVSS 8.8
- CVE-2026-10166: Edimax BR-6478AC command injection in formWlbasicmediumCVSS 6.3
- CVE-2026-10165: Edimax BR-6478AC stack overflow in formWanTcpipSetuphighCVSS 8.8
- CVE-2026-10164: Edimax BR-6478AC buffer overflow in formUSBFolderhighCVSS 8.8
Most severe Edimax vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-1316: Edimax IC-7100 IP Camera OS Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2026-19961: Edimax EW-7478APC buffer overflow in wireless site surveycriticalCVSS 9.9EPSS 0.8%
- CVE-2026-19959: Edimax EW-7478APC stack buffer overflow in WAN configurationcriticalCVSS 9.9EPSS 0.8%
- CVE-2026-36734: Edimax BR-6428nS V3 command injection in WLAN configurationhighCVSS 8.8EPSS 1.0%
- CVE-2026-9482: Edimax EW-7438RPn stack overflow in formSDHCPhighCVSS 8.8EPSS 0.0%
- CVE-2026-9481: Edimax EW-7438RPn stack overflow in formStatshighCVSS 8.8EPSS 0.0%
- CVE-2026-9480: Edimax EW-7438RPn stack overflow in formrefreshhighCVSS 8.8EPSS 0.0%
- CVE-2026-9479: Edimax EW-7438RPn stack overflow in formLogouthighCVSS 8.8EPSS 0.0%
- CVE-2026-9463: Edimax EW-7438RPn stack overflow in formLicencehighCVSS 8.8EPSS 0.0%
- CVE-2026-9462: Edimax EW-7438RPn stack overflow in formWpsProxyEnablehighCVSS 8.8EPSS 0.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 9 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 3 | 2 | |
| 17 Aug 2026 | 2 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 2 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 1 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/edimax.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Edimax vulnerabilities", https://junglewise.ai/threats/vendors/edimax, 26 September 2026.