Impact
A flaw in the setWAN function of the Edimax EW‑7478APC 1.04 firmware allows attackers to inject arbitrary system commands by manipulating the pppUserName, pptpUserName, or L2TPUserName arguments. This results in remote command execution, granting an attacker full control over the device. The flaw stems from insufficient input validation and is classified under CWE‑74 and CWE‑77.
Affected Systems
Edimax EW‑7478APC wireless access point running firmware version 1.04 is vulnerable. The issue affects the setWAN command accessible via /goform/setWAN. No other firmware versions or products are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, but an exploit has already been published and can be performed remotely, as indicated in the CVE description. The vulnerability is not listed in the CISA KEV catalog, suggesting it may be less widely exploited yet remains a significant risk, especially for devices exposed to untrusted networks.
OpenCVE Enrichment