Description
A security flaw has been discovered in Edimax BR-6214K 1.40. This vulnerability affects the function system of the file www/ping.asp of the component asp_setPing Endpoint. Performing a manipulation of the argument pingstr results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-31
Score: 5.1 Medium
EPSS: 2.1% Low
KEV: No
Impact: OS Command Injection
Action: Apply Fix
AI Analysis

Impact

A flaw in the Edimax BR‑6214K firmware allows an attacker to control the pingstr argument in the www/ping.asp page. By sending a crafted value, remote users can inject arbitrary operating‑system commands that the device executes, leading to loss of confidentiality, integrity, or availability of the device and potentially the network it connects to.

Affected Systems

The vulnerability is confirmed in Edimax BR‑6214K firmware version 1.40. No other affected versions are listed in the current data.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity, while the EPSS score is 2% and the flaw is not in the CISA KEV catalog. The attack vector is remote, as the exploit can be triggered through the web interface. An attacker could use the injection to run any command the device operates under, potentially compromising the device, logging credentials, or inserting other malicious commands. The publicly available exploit indicates that adversaries may already be attempting to use this weakness.

Generated by OpenCVE AI on September 1, 2026 at 15:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest official Edimax firmware update that addresses the command injection flaw.
  • Restrict or block HTTP access to the www/ping.asp endpoint from untrusted networks using the device’s firewall or network segmentation.
  • Monitor system logs for unusual command execution patterns and investigate potential signs of exploitation.

Generated by OpenCVE AI on September 1, 2026 at 15:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Edimax BR-6214K 1.40. This vulnerability affects the function system of the file www/ping.asp of the component asp_setPing Endpoint. Performing a manipulation of the argument pingstr results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Edimax BR-6214K asp_setPing Endpoint ping.asp system os command injection
First Time appeared Edimax
Edimax br-6214k
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:edimax:br-6214k:*:*:*:*:*:*:*:*
Vendors & Products Edimax
Edimax br-6214k
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.6, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T21:58:04.333Z

Reserved: 2026-08-30T18:27:32.519Z

Link: CVE-2026-82703

cve-icon Vulnrichment

Updated: 2026-08-31T21:50:18.217Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T15:18:12.503

Modified: 2026-08-31T22:17:30.823

Link: CVE-2026-82703

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T15:45:05Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')