PT-2024-10392 · Edimax · Edimax Ac1200 Wi-Fi 5 Dual-Band Router Br-6476Ac
Published
2024-06-18
·
Updated
2026-05-10
·
CVE-2024-48419
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Edimax AC1200 Wi-Fi 5 Dual-Band router BR-6476AC version 1.06
Description
The issue is related to command injection problems in /bin/goahead, which can be triggered through API endpoints such as "/goform/tracerouteDiagnosis", "/goform/pingDiagnosis", and "/goform/fromSysToolPingCmd". These problems allow an attacker with access to the web interface to inject and execute arbitrary shell commands with "root" or "superusuario" privileges. The vulnerability is associated with a lack of data sanitization on the management level, allowing a remote attacker to elevate privileges and execute arbitrary commands.
Recommendations
For Edimax AC1200 Wi-Fi 5 Dual-Band router BR-6476AC version 1.06, consider disabling access to the vulnerable API endpoints "/goform/tracerouteDiagnosis", "/goform/pingDiagnosis", and "/goform/fromSysToolPingCmd" until a patch is available. Restrict access to the web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edimax Ac1200 Wi-Fi 5 Dual-Band Router Br-6476Ac