CVE-2025-70161
PoC nicheUnauthenticated Command Injection in Edimax BR-6208AC V2 Firmware 1.02
Edimax BR-6208AC V2 routers running firmware 1.02 (V2_1.02) are vulnerable to OS command injection (CWE-77): the web interface's setWAN handler passes the PPPoE pppUserName field directly to the system() function without sanitization. An attacker who can reach the router's web management interface can submit a crafted PPPoE username containing shell metacharacters, causing arbitrary commands to execute on the device. Successful exploitation yields full router compromise with high impact on confidentiality, integrity, and availability (CVSS 3.1 9.8), and a foothold for further attacks such as traffic interception or pivoting into the LAN. Only Edimax BR-6208AC V2 devices on the affected firmware are implicated, with exposure driven chiefly by whether the management interface is reachable from untrusted networks such as the WAN side. No in-the-wild exploitation is confirmed and the flaw is not in CISA's KEV, but a public proof-of-concept writeup exists and EPSS assigns a 27.1% probability of exploitation within 30 days (98th percentile), making it a near-term risk.
What to do: Inventory Edimax BR-6208AC V2 devices and check the running firmware version; if it is 1.02, apply a vendor firmware update when one becomes available (no fixed version is documented in the current data). Until patched, do not expose the router's web management interface to the WAN or other untrusted networks, disable remote administration, and avoid PPPoE credentials containing shell metacharacters where possible. No exploitation is confirmed in the wild, but given the elevated EPSS score, monitor Edimax advisories and treat WAN-reachable units as priority targets.
| Edimax BR-6208AC V2 router firmware | V2_1.02 (firmware 1.02 is the only version identified; other versions are not documented in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbitrary code execution.
- Vendors
- edimax
- Products
- br-6208ac firmware
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.