Description
A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of the file /goform/formAccept of the component POST Request Handler. Such manipulation of the argument submit-url leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-05-25
Score: 5.3 Medium
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a classic command injection vulnerability in Edimax BR‑6478AC firmware 1.23, exercised through the formAccept route of the POST Request Handler. By tampering with the submit-url parameter an attacker can inject arbitrary shell commands, potentially allowing full remote execution on the device. The weakness is identified as CWE‑74 (Command Injection) and CWE‑77 (Improper Permission Management).

Affected Systems

The affected product is the Edimax BR‑6478AC wireless router running firmware version 1.23. No other versions or variants are listed as affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. The exploit is publicly available and can be launched remotely over HTTP, implying that any network-accessible device could be compromised if no mitigation is applied.

Generated by OpenCVE AI on May 25, 2026 at 09:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router firmware to a patched version that disables or sanitizes the submit‑url parameter in the formAccept endpoint.
  • If a firmware update is not yet released, block or filter outbound HTTP POST requests to the /goform/formAccept URI using a firewall or router ACL, effectively preventing remote command injection attempts.
  • Disable any remote management or web interface features when the device is not actively required, or isolate the router in a segregated network segment to reduce exposure.

Generated by OpenCVE AI on May 25, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 28 May 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 25 May 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Edimax br-6478ac
Vendors & Products Edimax br-6478ac

Mon, 25 May 2026 08:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of the file /goform/formAccept of the component POST Request Handler. Such manipulation of the argument submit-url leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Edimax BR-6478AC POST Request formAccept command injection
First Time appeared Edimax
Edimax br-6478ac Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:edimax:br-6478ac_firmware:*:*:*:*:*:*:*:*
Vendors & Products Edimax
Edimax br-6478ac Firmware
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Edimax Br-6478ac Br-6478ac Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-28T18:00:40.914Z

Reserved: 2026-05-24T07:25:52.979Z

Link: CVE-2026-9440

cve-icon Vulnrichment

Updated: 2026-05-28T18:00:24.266Z

cve-icon NVD

Status : Deferred

Published: 2026-05-25T08:16:25.903

Modified: 2026-05-26T19:37:00.120

Link: CVE-2026-9440

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T09:30:21Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')