Impact
A function named stainfo in the /goform/stainfo interface of Edimax EW-7478APC firmware version 1.04 is vulnerable to argument manipulation that permits the execution of arbitrary commands. The weakness is an example of improper input validation (CWE-74) and improper use of system command execution (CWE-77). When exploited, an attacker can achieve remote code execution against the device, potentially compromising confidentiality, integrity, and availability of the network segment housing the router.
Affected Systems
The affected vendor is Edimax, product EW-7478APC, firmware release 1.04. No other versions are listed in the available data.
Risk and Exploitability
The CVSS v3 score of 5.3 indicates a moderate impact; no EPSS score is publicly available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote network access to the web interface, as the command injection can be triggered by manipulating the argument passed to the stainfo endpoint. Since the vendor has not released a patch or response, the risk remains if the device is exposed to the Internet or untrusted local networks.
OpenCVE Enrichment