Impact
The vulnerability is found in the mp function of the /goform/mp endpoint in Edimax BR-6478AC V2 firmware 1.23. By manipulating the "command" parameter in a POST request, an attacker can inject arbitrary system commands. This injection allows remote execution of commands on the device, potentially granting full control to the attacker.
Affected Systems
Edimax BR-6478AC V2 firmware version 1.23 is affected. No other vendor or product versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is unavailable, but the exploit is publicly released and can be triggered remotely via a simple POST request to /goform/mp, without any authentication. The vulnerability is not currently listed in the CISA KEV catalog. Consequently, any unpatched device accessible over the network is at risk of compromise.
OpenCVE Enrichment