PT-2026-36685 · Edimax · Br-6208Ac
Tian
·
Published
2026-05-03
·
Updated
2026-05-03
·
CVE-2026-7682
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Edimax BR-6208AC version 1.02
Description
A command injection flaw exists in the L2TP Mode component. The issue occurs within the
setWAN() function of the '/goform/setWAN' endpoint. A remote attacker can exploit this by manipulating the L2TPUserName argument to execute arbitrary commands.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the '/goform/setWAN' endpoint or avoid using the
L2TPUserName parameter in the L2TP Mode component.Exploit
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Br-6208Ac