Description
A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function stainfo of the file /goform/stainfo. The manipulation of the argument interface leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-16
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A function named stainfo in the /goform/stainfo interface of Edimax EW-7478APC firmware version 1.04 is vulnerable to argument manipulation that permits the execution of arbitrary commands. The weakness is an example of improper input validation (CWE-74) and improper use of system command execution (CWE-77). When exploited, an attacker can achieve remote code execution against the device, potentially compromising confidentiality, integrity, and availability of the network segment housing the router.

Affected Systems

The affected vendor is Edimax, product EW-7478APC, firmware release 1.04. No other versions are listed in the available data.

Risk and Exploitability

The CVSS v3 score of 5.3 indicates a moderate impact; no EPSS score is publicly available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote network access to the web interface, as the command injection can be triggered by manipulating the argument passed to the stainfo endpoint. Since the vendor has not released a patch or response, the risk remains if the device is exposed to the Internet or untrusted local networks.

Generated by OpenCVE AI on August 17, 2026 at 00:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest firmware update from Edimax that addresses the command injection flaw
  • Limit access to the /goform/stainfo endpoint by placing the device behind a strict firewall or disabling remote management
  • Implement input validation or sanitization at the web interface to prevent malformed arguments from reaching system commands

Generated by OpenCVE AI on August 17, 2026 at 00:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 16 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function stainfo of the file /goform/stainfo. The manipulation of the argument interface leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Edimax EW-7478APC stainfo command injection
First Time appeared Edimax
Edimax ew-7478apc
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:edimax:ew-7478apc:*:*:*:*:*:*:*:*
Vendors & Products Edimax
Edimax ew-7478apc
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Edimax Ew-7478apc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-16T23:30:10.002Z

Reserved: 2026-08-16T07:07:53.770Z

Link: CVE-2026-19963

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T00:16:27.137

Modified: 2026-08-17T00:16:27.137

Link: CVE-2026-19963

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T00:30:02Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')