Impact
A command injection flaw exists in the formWizSurvey page of the Edimax EW‑7438RPn router, triggered by manipulating the ip/mask/gateway parameters. The flaw permits an unauthenticated attacker to inject and execute arbitrary operating‑system commands on the device. If exploited, an attacker could gain full control, compromise confidentiality, integrity, and availability of the router, and potentially use the device as a foothold for further network attacks.
Affected Systems
The vulnerability affects Edimax EW‑7438RPn routers running firmware versions up to 1.31. No other hardware or software is listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog. Exploitation code has been publicly disclosed, and the vulnerability can be triggered remotely via the router’s web interface, making it exploitable by attackers who can reach the device over the network.
OpenCVE Enrichment