MEDIUM
Edimax BR-6478AC POST Request formWlbasic command injection
Published May 31, 2026
5.3
MEDIUMCVSS 4.0
EPSS 1.07%
Description
A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. This manipulation of the argument rootAPmac causes command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected products
-
- Version 1.23StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://lavender-bicycle-a5a.notion.site/EDIMAX-BR6478ACV2-formWlbasic-34b53a41781f80edb1e5e0104741dfb2?source=copy_link exploit
- https://vuldb.com/submit/818623 third-party-advisory
- https://vuldb.com/vuln/367418 vdb-entrytechnical-description
- https://vuldb.com/vuln/367418/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://lavender-bicycle-a5a.notion.site/EDIMAX-BR6478ACV2-formWlbasic-34b53a41781f80edb1e5e0104741dfb2?source=copy_link | exploit | |
| https://vuldb.com/submit/818623 | third-party-advisory | |
| https://vuldb.com/vuln/367418 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/367418/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published May 31, 2026
Updated Jun 1, 2026
Reserved May 30, 2026
Link CVE-2026-10166
CISA Vulnrichment
Updated Jun 1, 2026