PT-2025-16345 · Edimax · Edimax Ac1200 Wave 2 Dual-Band Gigabit Router Br-6478Ac

Regainer27

·

Published

2025-04-14

·

Updated

2026-05-25

·

CVE-2025-28142

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC version V3 1.0.15
Description A command injection issue exists due to a lack of input validation. This allows a remote attacker to execute arbitrary commands via the foldername variable in the '/boafrm/formDiskCreateShare' endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-14792
CVE-2025-28142

Affected Products

Edimax Ac1200 Wave 2 Dual-Band Gigabit Router Br-6478Ac