Description
A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component goform Handler. Executing a manipulation of the argument submit-url can lead to open redirect. The attack may be launched remotely. The exploit has been published and may be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-24
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Open Redirect
Action: Patch
AI Analysis

Impact

The vulnerability is an open redirect flaw in the websRedirect function of the goform handler on Edimax BR‑6428nC routers running firmware 1.16. By manipulating the submit‑url argument, an attacker can redirect users to arbitrary destinations. This flaw is remotely exploitable and an exploit has been published, meaning it could be used in the wild.

Affected Systems

Affected are Edimax BR‑6428nC routers with firmware version 1.16. Multiple web endpoints that invoke the goform handler are susceptible, but the primary impact targets the device’s public web interface used for remote configuration.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, but the existence of a published exploit suggests the risk is non‑trivial. The vulnerability is not currently listed in CISA’s KEV catalogue. Attack vectors are remote web interfaces, so any device exposed to the internet could be targeted.

Generated by OpenCVE AI on September 24, 2026 at 04:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review Edimax’s official advisories or support channels for any firmware update or notice that addresses the open redirect flaw in the goform handler.
  • If no patch is available, restrict remote access to the router’s web interface by placing it behind a firewall or VPN and limiting it to trusted networks.
  • Activate monitoring on web traffic logs for unexpected redirect attempts and configure alerts for administrators to detect potential exploitation.

Generated by OpenCVE AI on September 24, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component goform Handler. Executing a manipulation of the argument submit-url can lead to open redirect. The attack may be launched remotely. The exploit has been published and may be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.
Title Edimax BR-6428nC goform websRedirect redirect
First Time appeared Edimax
Edimax br-6428nc
Weaknesses CWE-601
CPEs cpe:2.3:a:edimax:br-6428nc:*:*:*:*:*:*:*:*
Vendors & Products Edimax
Edimax br-6428nc
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Edimax Br-6428nc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-24T12:49:51.062Z

Reserved: 2026-09-23T19:29:38.464Z

Link: CVE-2026-96892

cve-icon Vulnrichment

Updated: 2026-09-24T12:49:08.397Z

cve-icon NVD

Status : Deferred

Published: 2026-09-24T04:18:04.790

Modified: 2026-09-24T14:40:36.103

Link: CVE-2026-96892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T05:00:13Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')