Impact
A flaw in the Edimax BR‑6214K firmware allows an attacker to control the pingstr argument in the www/ping.asp page. By sending a crafted value, remote users can inject arbitrary operating‑system commands that the device executes, leading to loss of confidentiality, integrity, or availability of the device and potentially the network it connects to.
Affected Systems
The vulnerability is confirmed in Edimax BR‑6214K firmware version 1.40. No other affected versions are listed in the current data.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity, while the EPSS score is 2% and the flaw is not in the CISA KEV catalog. The attack vector is remote, as the exploit can be triggered through the web interface. An attacker could use the injection to run any command the device operates under, potentially compromising the device, logging credentials, or inserting other malicious commands. The publicly available exploit indicates that adversaries may already be attempting to use this weakness.
OpenCVE Enrichment