PT-2024-10392 · Edimax · Edimax Ac1200 Wi-Fi 5 Dual-Band Router Br-6476Ac

Published

2024-06-18

·

Updated

2026-05-10

·

CVE-2024-48419

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Edimax AC1200 Wi-Fi 5 Dual-Band router BR-6476AC version 1.06
Description The issue is related to command injection problems in /bin/goahead, which can be triggered through API endpoints such as "/goform/tracerouteDiagnosis", "/goform/pingDiagnosis", and "/goform/fromSysToolPingCmd". These problems allow an attacker with access to the web interface to inject and execute arbitrary shell commands with "root" or "superusuario" privileges. The vulnerability is associated with a lack of data sanitization on the management level, allowing a remote attacker to elevate privileges and execute arbitrary commands.
Recommendations For Edimax AC1200 Wi-Fi 5 Dual-Band router BR-6476AC version 1.06, consider disabling access to the vulnerable API endpoints "/goform/tracerouteDiagnosis", "/goform/pingDiagnosis", and "/goform/fromSysToolPingCmd" until a patch is available. Restrict access to the web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-00902
CVE-2024-48419

Affected Products

Edimax Ac1200 Wi-Fi 5 Dual-Band Router Br-6476Ac