Impact
This vulnerability is a command injection in the Edimax BR‑6478AC firmware 1.23 that occurs when an attacker manipulates the rootAPmac argument of the /goform/formiNICbasic POST handler. The flaw allows arbitrary system commands to be executed on the device, granting an attacker full control. The underlying weaknesses correspond to CWE‑74 and CWE‑77, which relate to unconstrained command execution and improper input validation. The public availability of an exploit means a threat actor could remotely compromise affected units without any user interaction.
Affected Systems
The affected product is the Edimax BR‑6478AC router running firmware version 1.23. No other firmware revisions are listed as vulnerable in the current data.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, but the fact that the flaw can be triggered remotely and that a public exploit already exists elevates the practical risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can reach the vulnerable endpoint over HTTP from outside the network, making the risk realistic for exposed devices.
OpenCVE Enrichment