← Back

Edimax

edimax

66 CVEs • 46 products

Products (46)

Click to collapse
Toggle
Br 6104k
br_6104k
6114wg
Ic 3140w
ic-3140w
Ic 5150w
ic-5150w
Ic 6220dc
ic-6220dc
7237rpd
Br 6208ac V1
br-6208ac_v1
Ic 3116w
ic-3116w
Br 6428ns
br-6428ns
Br 6288acl
br-6288acl
Br 6478ac
br-6478ac
Re11s
re11s
Br 6476ac
br-6476ac
Ic 7100
ic-7100
Br 6478ac V3
br-6478ac_v3
Cv 7428ns
cv-7428ns
Br 6473ax
br-6473ax
Br 6208ac
br-6208ac
Br 6208ac V2
br-6208ac_v2
Br 6258n
br-6258n
Gs 5008pl
gs-5008pl

CVEs (66)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Edimax
1Br 6478ac V3 Firmware
Jun 17, 2026
Dec 5, 2025
2.0 LOW· v4
7.2 HIGH· v3
5.8 MEDIUM· v2
A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. This issue affects the function sub_416898 of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to os command i...Show more
A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. This issue affects the function sub_416898 of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Edimax
1Br 6473ax Firmware
Jun 17, 2026
Sep 16, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter in the openwrt_getConfig function.
1Edimax
1Ew 7438rpn Mini Firmware
Jun 17, 2026
Jun 20, 2025
9.4 CRITICAL· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscmd.asp form handler. The /goform/formSysCmd endpoint exposes a system command interface through the s...Show more
An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscmd.asp form handler. The /goform/formSysCmd endpoint exposes a system command interface through the sysCmd parameter. A remote authenticated attacker can submit arbitrary shell commands directly, resulting in command execution as the root user. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-14 UTC.Show less
1Edimax
1Ew 7438rpn Mini Firmware
Jun 17, 2026
Jun 20, 2025
9.4 CRITICAL· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter....Show more
An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters to achieve arbitrary command execution as the root user. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-14 UTC.Show less
1Edimax
1Cv 7428ns Firmware
Jun 17, 2026
May 13, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.
1Edimax
1Re11s Firmware
Jun 17, 2026
Apr 15, 2025
N/A· v4
5.6 MEDIUM· v3
N/A· v2
RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function.
1Edimax
1Br 6478ac V3 Firmware
Jun 17, 2026
Apr 15, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafrm/formDiskFormat.
1Edimax
1Br 6478ac V3 Firmware
Jun 17, 2026
Apr 15, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerability via peerPin parameter in the formWsc function.
1Edimax
1Br 6478ac V3 Firmware
Jun 17, 2026
Apr 15, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at the /boafrm/formDiskCreateGroup.
1Edimax
1Br 6478ac V3 Firmware
Jun 17, 2026
Apr 15, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /boafrm/formDiskCreateShare.
1Edimax
1Br 6478ac V3 Firmware
Jun 17, 2026
Apr 4, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel
1Edimax
1Ic 7100 Firmware
Jun 17, 2026
Mar 5, 2025
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device
1Edimax
1Br 6288acl Firmware
Jun 17, 2026
Feb 24, 2025
5.1 MEDIUM· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in Edimax BR-6288ACL 1.30. It has been declared as problematic. This vulnerability affects unknown code of the file wireless5g_basic.asp. The manipulation of the argument SSID leads to cross sit...Show more
A vulnerability was found in Edimax BR-6288ACL 1.30. It has been declared as problematic. This vulnerability affects unknown code of the file wireless5g_basic.asp. The manipulation of the argument SSID leads to cross site scripting. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Edimax
1Br 6476ac Firmware
Jul 5, 2026
Jan 27, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/getWifiBasic.
1Edimax
1Br 6476ac Firmware
Jul 5, 2026
Jan 27, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /go...Show more
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an attacker with access to the web interface to inject and execute arbitrary shell commands, with "root" privileges.Show less
1Edimax
1Br 6476ac Firmware
Jul 5, 2026
Jan 27, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interf...Show more
In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.Show less
1Edimax
1Br 6476ac Firmware
Jul 5, 2026
Jan 27, 2025
N/A· v4
5.2 MEDIUM· v3
N/A· v2
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Cross Site Scripting (XSS) in : /bin/goahead via /goform/setStaticRoute, /goform/fromSetFilterUrlFilter, and /goform/fromSetFilterClientFilter.
1Edimax
1Br 6476ac Firmware
Jul 5, 2026
Jan 27, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/fromSetLanDhcpsClientbinding.
1Edimax
1Re11s Firmware
Jul 5, 2026
Jan 16, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.
1Edimax
1Re11s Firmware
Jun 17, 2026
Jan 16, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function.