Description
A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipulation of the argument pppUserName/pptpUserName/L2TPUserName can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-16
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the setWAN function of the Edimax EW‑7478APC 1.04 firmware allows attackers to inject arbitrary system commands by manipulating the pppUserName, pptpUserName, or L2TPUserName arguments. This results in remote command execution, granting an attacker full control over the device. The flaw stems from insufficient input validation and is classified under CWE‑74 and CWE‑77.

Affected Systems

Edimax EW‑7478APC wireless access point running firmware version 1.04 is vulnerable. The issue affects the setWAN command accessible via /goform/setWAN. No other firmware versions or products are listed as affected.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, but an exploit has already been published and can be performed remotely, as indicated in the CVE description. The vulnerability is not listed in the CISA KEV catalog, suggesting it may be less widely exploited yet remains a significant risk, especially for devices exposed to untrusted networks.

Generated by OpenCVE AI on August 17, 2026 at 00:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Edimax firmware that contains a fix for the command injection flaw.
  • Restrict external access to the /goform/setWAN endpoint by configuring the device's firewall or ACLs to block or limit remote traffic.
  • Disable remote web administration or enforce strong authentication controls to reduce exposure if a patch is not yet available.

Generated by OpenCVE AI on August 17, 2026 at 00:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 16 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipulation of the argument pppUserName/pptpUserName/L2TPUserName can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Edimax EW-7478APC setWAN command injection
First Time appeared Edimax
Edimax ew-7478apc
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:edimax:ew-7478apc:*:*:*:*:*:*:*:*
Vendors & Products Edimax
Edimax ew-7478apc
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Edimax Ew-7478apc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-16T23:15:11.641Z

Reserved: 2026-08-16T07:07:49.713Z

Link: CVE-2026-19962

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T00:16:26.490

Modified: 2026-08-17T00:16:26.490

Link: CVE-2026-19962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T00:30:02Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')