MEDIUM
Edimax BR-6208AC L2TP Mode setWAN command injection
Published May 3, 2026
5.3
MEDIUMCVSS 4.0
EPSS 2.38%
Description
A security flaw has been discovered in Edimax BR-6208AC 1.02. The impacted element is the function setWAN of the file /goform/setWAN of the component L2TP Mode. The manipulation of the argument L2TPUserName results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 1.02StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26820 Advisory
- https://tzh00203.notion.site/Edimax-BR-6208AC-V2-1-02-setWAN-L2TPUserName-Command-Injection-33db5c52018a80c1b3aac6db8927bd0f exploit
- https://vuldb.com/submit/801572 third-party-advisory
- https://vuldb.com/vuln/360841 vdb-entrytechnical-description
- https://vuldb.com/vuln/360841/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26820 | Advisory | |
| https://tzh00203.notion.site/Edimax-BR-6208AC-V2-1-02-setWAN-L2TPUserName-Command-Injection-33db5c52018a80c1b3aac6db8927bd0f | exploit | |
| https://vuldb.com/submit/801572 | third-party-advisory | |
| https://vuldb.com/vuln/360841 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/360841/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published May 3, 2026
Updated May 5, 2026
Reserved May 2, 2026
Link CVE-2026-7682
CISA Vulnrichment
Updated May 5, 2026
ENISA EUVD
EUVD-2026-26820 Assigner VulDB
Published May 3, 2026
Updated May 5, 2026
Exploited since n/a
Link EUVD-2026-26820