CVE-2026-12808: Command Injection in Edimax BR-6478AC V2 Firmware 1.23
A command injection vulnerability has been discovered in Edimax BR-6478AC V2 running firmware version 1.23. An authenticated attacker can manipulate the 'interface' parameter in a POST request to the /goform/stainfo endpoint to execute arbitrary system commands. The vulnerability requires valid login credentials but poses a meaningful risk to organizations relying on this router model, particularly in environments where user accounts may be compromised or where trust boundaries are weak.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Weaknesses (CWE)
- CWE-74, CWE-77
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-21 / 2026-06-22
NVD description (verbatim)
A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainfo of the component POST Request Handler. This manipulation of the argument interface causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
5 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability exists in the stainfo POST request handler of the Edimax BR-6478AC V2 router. The application fails to properly sanitize the 'interface' argument before passing it to system command execution functions. This classic command injection flaw (CWE-74: Improper Neutralization of Special Elements in Output; CWE-77: Improper Neutralization of Special Elements used in a Command) allows an authenticated user to break out of the intended command context and execute arbitrary shell commands with the privileges of the web service process. The attack surface is network-accessible and requires only standard HTTP POST capabilities.
Business impact
Compromise of an Edimax BR-6478AC V2 router enables an attacker to gain command-level control over network infrastructure. Potential consequences include unauthorized access to internal network traffic, lateral movement to connected systems, exfiltration of sensitive data, deployment of malware or persistent backdoors, and denial of service. For organizations using these devices as primary or secondary network gateways—particularly in remote offices or branch locations—successful exploitation could compromise entire network segments.
Affected systems
This vulnerability specifically affects Edimax BR-6478AC V2 running firmware version 1.23. Organizations should inventory any instances of this router model and firmware version across their infrastructure. Other firmware versions of the same model and different Edimax router models may have similar or related issues, but this CVE addresses only the v1.23 variant.
Exploitability
Exploitation requires valid authentication credentials and network access to the router's web interface (typically port 80 or 443). While this is not a zero-day or unauthenticated vulnerability, the barrier to exploitation is modest—weak default credentials, credential reuse, or insider threats substantially lower practical difficulty. The exploit has been publicly disclosed, meaning threat actors possess working proof-of-concept code and detailed technical information. Active exploitation should be anticipated.
Remediation
Check the Edimax support website for a firmware update beyond version 1.23 that addresses this command injection flaw. If no patched version is available or the device is end-of-life, consider replacing it with a router from a vendor with active security support. In the interim, implement network segmentation to restrict administrative access to the router's web interface to trusted IP ranges only, and enforce strong, unique passwords on all administrative accounts.
Patch guidance
Verify that Edimax has released a patched firmware version for the BR-6478AC V2. Download any available update directly from the Edimax website and follow their documented upgrade procedure. If no patch is publicly available, contact Edimax support with CVE-2026-12808 as a reference. Note that the vendor was contacted early but did not respond, which may indicate limited or delayed patching availability. In such cases, prioritize network access controls and monitoring as compensating controls.
Detection guidance
Monitor for POST requests to /goform/stainfo with unusual or suspicious values in the 'interface' parameter, particularly those containing shell metacharacters (semicolons, pipes, backticks, command substitution syntax). Log and alert on successful authentication followed by requests to this endpoint. Review router access logs for administrative logins from unexpected IP addresses. Consider implementing a Web Application Firewall (WAF) rule to block requests with command injection payloads to this endpoint, if your infrastructure supports it.
Why prioritize this
Although this vulnerability requires authentication, its network-accessible nature, public disclosure, and command injection severity justify medium-priority remediation. The CVSS 3.1 score of 6.3 reflects the combination of low barrier to exploitation (once authenticated) and moderate impact. Organizations should address this within 30 days, particularly if the affected router has internet-facing administrative interfaces or is deployed in environments with elevated insider risk.
Risk score, explained
The CVSS 3.1 score of 6.3 (Medium) reflects: attack vector network-accessible, attack complexity low (straightforward exploitation), privilege level low (requires authentication), no user interaction needed, scope unchanged to the vulnerable component, and confidentiality/integrity/availability impacts all rated as low. The score appropriately captures that while command injection is fundamentally dangerous, the requirement for prior authentication prevents a critical rating. In practice, risk may be higher or lower depending on the robustness of authentication controls and the router's network exposure.
Frequently asked questions
Does this vulnerability require internet-facing access to exploit?
No, but the attacker must be able to reach the router's web interface, typically via HTTP/HTTPS on the LAN. If the router's management interface is exposed to the internet or accessible via VPN without additional controls, remote exploitation from outside the network is possible.
Can this vulnerability be exploited without a valid login?
No, the CVSS vector indicates PR:L (privilege level low), meaning a valid authenticated session or credentials are required. Default credentials, compromised user accounts, or weak passwords substantially increase practical risk.
What should I do if my organization uses this router model?
Immediately check your inventory for BR-6478AC V2 units running firmware 1.23. Verify whether Edimax has released a patched firmware version. If a patch is available, schedule a maintenance window and apply it. If no patch exists, restrict administrative access via network segmentation and strong access controls, and plan for device replacement.
Is exploitation being actively observed in the wild?
The vulnerability description notes that the exploit has been publicly disclosed, which means threat actors have access to working code and detailed technical information. While this CVE is not on the CISA Known Exploited Vulnerabilities (KEV) catalog, active exploitation should be presumed likely given the public disclosure and moderate ease of exploitation.
This vulnerability intelligence is current as of the published date and reflects information available from the CVE record and associated sources. Edimax was contacted early regarding this disclosure but did not provide a response; patch availability and timeline are uncertain. Organizations should verify all patch information directly from the vendor before deploying updates. This analysis does not constitute legal, compliance, or specific operational advice for your environment. Security teams should validate applicability to their infrastructure and threat model. No exploit code or step-by-step weaponization details are provided in this document. Source: NVD (public-domain), retrieved 2026-07-28. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10060MEDIUMTRENDnet TEW-432BRP Command Injection—End-of-Life Router Vulnerability
- CVE-2026-10061MEDIUMTRENDnet TEW-432BRP Command Injection Vulnerability – Remediation via Replacement
- CVE-2026-10127MEDIUMEdimax BR-6478AC Command Injection in Firmware 1.23
- CVE-2026-10166MEDIUMEdimax BR-6478AC Command Injection – Authentication Required
- CVE-2026-10180MEDIUMTRENDnet TEW-432BRP Command Injection Vulnerability – Hardware Retirement Required
- CVE-2026-10182MEDIUMTRENDnet TEW-432BRP Command Injection – Unpatched EOL Device
- CVE-2026-10550MEDIUMCommand Injection in elunez eladmin Deployment Module
- CVE-2026-10878MEDIUMD-Link DWR-M920 Command Injection Vulnerability – Patch Now