CVE-2025-14094
PoC moderateRemote OS Command Injection in Edimax BR-6478AC V3 Router Web Interface
CVE-2025-14094 is an OS command injection flaw (CWE-77/CWE-78) in the sysCmd parameter processed by the formSysCmd handler (function sub_44CCE4) of the boa web server on the Edimax BR-6478AC V3 running firmware 1.0.15. A remote attacker can trigger it by sending a crafted request to /boafrm/formSysCmd with malicious content in the sysCmd argument; per the CVSS 4.0 vector, high privileges (administrator-level access to the web management interface) are required and no user interaction is needed. Successful exploitation lets the attacker execute arbitrary operating-system commands on the router, compromising the device's confidentiality, integrity, and availability (each rated low in the base score, though device-level control is the practical risk). Only Edimax BR-6478AC V3 deployments on the disclosed firmware version are confirmed affected, and the vendor was contacted early about the issue but did not respond in any way. A public proof-of-concept has been published on GitHub, EPSS assigns a 20.3% probability of exploitation within 30 days (97th percentile), and the flaw is not yet listed in CISA KEV.
What to do: No fixed firmware version has been announced because the vendor did not respond to the disclosure, so verify your current firmware (1.0.15 is the confirmed affected version) and watch for an Edimax firmware update. Until a patch is available, avoid exposing the router's web management interface to the internet, restrict administrative access to trusted hosts, and use a strong, unique administrator password since exploitation requires admin privileges. Given the 20.3% EPSS score, treat this as a near-term exploitation risk for any internet-facing BR-6478AC V3 units and monitor them for signs of compromise.
| Edimax BR-6478AC V3 router firmware | 1.0.15 (confirmed affected; other versions not specified in the disclosure) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm/formSysCmd. This manipulation of the argument sysCmd causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- edimax
- Products
- br-6478ac v3 firmware
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.