Impact
The vulnerability is an open redirect flaw in the websRedirect function of the goform handler on Edimax BR‑6428nC routers running firmware 1.16. By manipulating the submit‑url argument, an attacker can redirect users to arbitrary destinations. This flaw is remotely exploitable and an exploit has been published, meaning it could be used in the wild.
Affected Systems
Affected are Edimax BR‑6428nC routers with firmware version 1.16. Multiple web endpoints that invoke the goform handler are susceptible, but the primary impact targets the device’s public web interface used for remote configuration.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, but the existence of a published exploit suggests the risk is non‑trivial. The vulnerability is not currently listed in CISA’s KEV catalogue. Attack vectors are remote web interfaces, so any device exposed to the internet could be targeted.
OpenCVE Enrichment