PT-2025-16346 · Edimax · Edimax Ac1200 Wave 2 Dual-Band Gigabit Router Br-6478Ac

Regainer27

·

Published

2025-04-15

·

Updated

2026-05-25

·

CVE-2025-28143

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC version V3 1.0.15
Description The web interface of the firmware contains a command injection issue due to insufficient data sanitization at the control level. A remote attacker can exploit this by sending crafted data to the '/boafrm/formDiskCreateGroup' endpoint using the groupname parameter, which may allow the attacker to escalate privileges and execute arbitrary commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-04834
CVE-2025-28143

Affected Products

Edimax Ac1200 Wave 2 Dual-Band Gigabit Router Br-6478Ac