Impact
The flaw is an operating system command injection in the www/wlanMP.asp file of the Edimax BR-6214K router firmware. An attacker can manipulate the ateFunc request argument to inject arbitrary shell commands. If the injection succeeds, the attacker could execute any command with the privileges of the web service, enabling full control over the device, theft of data, or denial of service.
Affected Systems
Only the Edimax BR-6214K model (firmware version 1.40) is known to be affected. No other devices or firmware versions are listed as vulnerable.
Risk and Exploitability
The CVSS score is 5.1, indicating a moderate severity. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, but the attack can be performed remotely via HTTP and a public exploit already exists. The combination of remote reach, existing exploit code, and lack of patch availability results in a measurable but not critical risk compared to higher rating vulnerabilities.
OpenCVE Enrichment