PT-2026-36685 · Edimax · Br-6208Ac

Tian

·

Published

2026-05-03

·

Updated

2026-05-03

·

CVE-2026-7682

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Edimax BR-6208AC version 1.02
Description A command injection flaw exists in the L2TP Mode component. The issue occurs within the setWAN() function of the '/goform/setWAN' endpoint. A remote attacker can exploit this by manipulating the L2TPUserName argument to execute arbitrary commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the '/goform/setWAN' endpoint or avoid using the L2TPUserName parameter in the L2TP Mode component.

Exploit

Special Elements Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7682

Affected Products

Br-6208Ac