Impact
A command injection flaw exists in the setWAN function of the Edimax EW‑7478APC 1.04 firmware. The flaw arises when user input in the pppUserName, pptpUserName, or L2TPUserName fields is not properly validated, allowing an attacker to inject arbitrary shell commands. It is inferred that an attacker who can send a crafted request to /goform/setWAN can execute system commands on the device, giving remote command execution capabilities. This weakness is classified as CWE‑74 and CWE‑77.
Affected Systems
The vulnerability affects only the Edimax EW‑7478APC wireless access point running firmware version 1.04. No other firmware versions or other Edimax products are listed as affected in the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and an EPSS score of 1% denotes a low but non‑zero probability of exploitation. The exploit has been published, and the description confirms that an attacker can perform the attack from a remote location. The vulnerability is not listed in the CISA KEV catalog. Because of the combination of remote reachability and the ability to run arbitrary commands, the risk is significant for devices that are exposed to untrusted networks.
OpenCVE Enrichment