Impact
The flaw in the Edimax BR-6675nD 1.12 firmware allows a remote attacker to inject commands via the stainfo function exposed at the "/goform/stainfo" endpoint. This results in arbitrary command execution on the device, potentially compromising its integrity, confidentiality, and availability. The vulnerability is classified under CWE-74 and CWE-77, indicating unsafe handling of external input in command execution contexts. With a CVSS score of 5.3, the vulnerability is of moderate severity but can be leveraged when the affected argument is manipulated.
Affected Systems
The affected product is the Edimax BR-6675nD wireless router. Only firmware version 1.12 is currently known to contain the unpatched implementation of the stainfo endpoint; other versions may be affected if they include the same code but are not explicitly listed.
Risk and Exploitability
The exploit can be performed remotely by sending a crafted request to "/goform/stainfo" from an external network. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests that large-scale exploitation has not been observed yet. Despite this, the lack of a vendor response and the availability of a public exploit mean that the risk remains real. Attackers with network access to the router could gain full control through command injection, so the risk of exploitation is considered moderate to high in a permissive environment.
OpenCVE Enrichment