Description
A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. Performing a manipulation of the argument rootAPmac results in command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-05-25
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a command injection in the Edimax BR‑6478AC firmware 1.23 that occurs when an attacker manipulates the rootAPmac argument of the /goform/formiNICbasic POST handler. The flaw allows arbitrary system commands to be executed on the device, granting an attacker full control. The underlying weaknesses correspond to CWE‑74 and CWE‑77, which relate to unconstrained command execution and improper input validation. The public availability of an exploit means a threat actor could remotely compromise affected units without any user interaction.

Affected Systems

The affected product is the Edimax BR‑6478AC router running firmware version 1.23. No other firmware revisions are listed as vulnerable in the current data.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, but the fact that the flaw can be triggered remotely and that a public exploit already exists elevates the practical risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can reach the vulnerable endpoint over HTTP from outside the network, making the risk realistic for exposed devices.

Generated by OpenCVE AI on May 25, 2026 at 10:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router firmware to the latest version released by the vendor that addresses the command injection flaw.
  • If a patched firmware is not yet available, block external access to the /goform/formiNICbasic endpoint using a firewall or network segmentation so that only trusted internal hosts can send POST requests.
  • Ensure that management interfaces are only reachable from trusted internal networks and, if possible, enable strong authentication to reduce the chance of exploitation.
  • As a temporary protective measure, implement input validation or a whitelist for the rootAPmac parameter on any custom firmware or proxy devices, thereby preventing arbitrary command execution.

Generated by OpenCVE AI on May 25, 2026 at 10:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 25 May 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Edimax br-6478ac
Vendors & Products Edimax br-6478ac

Mon, 25 May 2026 09:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. Performing a manipulation of the argument rootAPmac results in command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Edimax BR-6478AC POST Request formiNICbasic command injection
First Time appeared Edimax
Edimax br-6478ac Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:edimax:br-6478ac_firmware:*:*:*:*:*:*:*:*
Vendors & Products Edimax
Edimax br-6478ac Firmware
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Edimax Br-6478ac Br-6478ac Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-25T08:15:09.211Z

Reserved: 2026-05-24T07:25:56.032Z

Link: CVE-2026-9441

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T11:30:23Z

Weaknesses