Description
A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipulation of the argument pppUserName/pptpUserName/L2TPUserName can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-16
Score: 5.3 Medium
EPSS: 1.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection flaw exists in the setWAN function of the Edimax EW‑7478APC 1.04 firmware. The flaw arises when user input in the pppUserName, pptpUserName, or L2TPUserName fields is not properly validated, allowing an attacker to inject arbitrary shell commands. It is inferred that an attacker who can send a crafted request to /goform/setWAN can execute system commands on the device, giving remote command execution capabilities. This weakness is classified as CWE‑74 and CWE‑77.

Affected Systems

The vulnerability affects only the Edimax EW‑7478APC wireless access point running firmware version 1.04. No other firmware versions or other Edimax products are listed as affected in the CNA data.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and an EPSS score of 1% denotes a low but non‑zero probability of exploitation. The exploit has been published, and the description confirms that an attacker can perform the attack from a remote location. The vulnerability is not listed in the CISA KEV catalog. Because of the combination of remote reachability and the ability to run arbitrary commands, the risk is significant for devices that are exposed to untrusted networks.

Generated by OpenCVE AI on August 17, 2026 at 15:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor provided update or patch for the EW‑7478APC firmware 1.04 once it becomes available.
  • If no patch is available, block external access to the /goform/setWAN endpoint by configuring the device firewall or ACLs to limit traffic to trusted networks.
  • Disable remote web administration or enforce strong authentication and role‑based access controls to reduce the attack surface.
  • Enable logging for the /goform/setWAN endpoint and monitor logs for suspicious activity indicative of command injection attempts.

Generated by OpenCVE AI on August 17, 2026 at 15:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 16 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipulation of the argument pppUserName/pptpUserName/L2TPUserName can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Edimax EW-7478APC setWAN command injection
First Time appeared Edimax
Edimax ew-7478apc
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:edimax:ew-7478apc:*:*:*:*:*:*:*:*
Vendors & Products Edimax
Edimax ew-7478apc
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Edimax Ew-7478apc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-18T14:12:31.511Z

Reserved: 2026-08-16T07:07:49.713Z

Link: CVE-2026-19962

cve-icon Vulnrichment

Updated: 2026-08-18T14:12:26.198Z

cve-icon NVD

Status : Deferred

Published: 2026-08-17T00:16:26.490

Modified: 2026-08-20T12:48:10.287

Link: CVE-2026-19962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T15:45:03Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')