Impact
The flaw is a classic command injection vulnerability in Edimax BR‑6478AC firmware 1.23, exercised through the formAccept route of the POST Request Handler. By tampering with the submit-url parameter an attacker can inject arbitrary shell commands, potentially allowing full remote execution on the device. The weakness is identified as CWE‑74 (Command Injection) and CWE‑77 (Improper Permission Management).
Affected Systems
The affected product is the Edimax BR‑6478AC wireless router running firmware version 1.23. No other versions or variants are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. The exploit is publicly available and can be launched remotely over HTTP, implying that any network-accessible device could be compromised if no mitigation is applied.
OpenCVE Enrichment