ZeroHour

CVE-2024-48418

PoC
CVSS 3.1
8.8 high
EPSS
<1%p23
Published
()
Modified
Description

In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.

Vendors
edimax
Products
br-6476ac firmware
Weakness
CWE-352
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.