Impact
A vulnerability exists in the EW-7438RPn router’s form handling routine that allows attackers to inject arbitrary operating system commands through carefully crafted input arguments. The flaw involves parameters such as ateFunc, ateGain, e2pTxPower1, and others that are not properly sanitized before being passed to the system shell. This can lead to the execution of any command on the device with the privileges granted to the firmware process, potentially giving full control over the router and enabling further network exploitation.
Affected Systems
The affected product is the Edimax EW-7438RPn series router, firmware version 1.31. The vulnerability resides in the /goform/formWlanMP component of the Content‑Type handler. Only devices running the specified firmware are impacted; newer firmware versions may have resolved the issue, though the specific fixed version is not listed.
Risk and Exploitability
The reported CVSS score of 5.3 indicates moderate severity, but remote exploitation is possible, and publicly available exploits exist. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, so the likelihood of widespread exploitation is uncertain. Because the attack vector is remote and the exploitation path involves injecting commands via HTTP requests, an attacker with network access to the device could remotely compromise it, achieve full control, and pivot to other systems on the network.
OpenCVE Enrichment