ZeroHour

Vulnerabilities

61 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-32841
+4 in the same advisory: …32838 …32842 …32840 …32839
Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the manageme

Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the global authentication flag mechanism to gain administrative access without credentials after any user authenticates, enabling unauthorized password changes, firmware uploads, and configuration modifications.

NVD description · AI analysis pending
9.2
group max
<1%
  • edimax gs-5008pl firmware
CVE-2026-1972
A vulnerability was found in Edimax BR-6208AC 2_1.02.

A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Performing a manipulation of the argument Username/Password results in use of default credentials. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor confirms that the affected product is end-of-life. They confirm that they "will issue a consolidated Security Advisory on our official support website." This vulnerability only affects products that are no longer supported by the maintainer.

NVD description · AI analysis pending
5.5<1% PoC
  • edimax br-6208ac firmware
CVE-2026-1971
A vulnerability has been found in Edimax BR-6288ACL up to 1.12.

A vulnerability has been found in Edimax BR-6288ACL up to 1.12. Impacted is the function wiz_WISP24gmanual of the file wiz_WISP24gmanual.asp. Such manipulation of the argument manualssid leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor confirms that the affected product is end-of-life. They confirm that they "will issue a consolidated Security Advisory on our official support website." This vulnerability only affects products that are no longer supported by the maintainer.

NVD description · AI analysis pending
1.9<1% PoC
  • edimax br-6288acl firmware
CVE-2026-1970
A flaw has been found in Edimax BR-6258n up to 1.18.

A flaw has been found in Edimax BR-6258n up to 1.18. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup. This manipulation of the argument submit-url causes open redirect. The attack can be initiated remotely. The exploit has been published and may be used. The vendor confirms that the affected product is end-of-life. They confirm that they "will issue a consolidated Security Advisory on our official support website." This vulnerability only affects products that are no longer supported by the maintainer.

NVD description · AI analysis pending
2.0<1% PoC
  • edimax br-6258n firmware
CVE-2020-37125
+2 in the same advisory: …37150 …37149
Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /g

Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection payloads to download and execute malicious scripts on the device.

NVD description · AI analysis pending
9.3
group max
7% PoC
  • edimax ew-7438rpn mini firmware
CVE-2020-37097
+1 in the same advisory: …37096
Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file.

Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive information including WiFi network name and plaintext password stored in device configuration variables.

NVD description · AI analysis pending
8.7
group max
<1% PoC
  • edimax ew-7438rpn mini firmware
CVE-2025-70161
Unauthenticated Command Injection in Edimax BR-6208AC V2 Firmware 1.02

Edimax BR-6208AC V2 routers running firmware 1.02 (V2_1.02) are vulnerable to OS command injection (CWE-77): the web interface's setWAN handler passes the PPPoE pppUserName field directly to the system() function without sanitization. An attacker who can reach the router's web management interface can submit a crafted PPPoE username containing shell metacharacters, causing arbitrary commands to execute on the device. Successful exploitation yields full router compromise with high impact on confidentiality, integrity, and availability (CVSS 3.1 9.8), and a foothold for further attacks such as traffic interception or pivoting into the LAN. Only Edimax BR-6208AC V2 devices on the affected firmware are implicated, with exposure driven chiefly by whether the management interface is reachable from untrusted networks such as the WAN side. No in-the-wild exploitation is confirmed and the flaw is not in CISA's KEV, but a public proof-of-concept writeup exists and EPSS assigns a 27.1% probability of exploitation within 30 days (98th percentile), making it a near-term risk.

Do: Inventory Edimax BR-6208AC V2 devices and check the running firmware version; if it is 1.02, apply a vendor firmware update when one becomes available (no fixed version is documented in the current data). Until patched, do not expose the router's web management interface to the WAN or other untrusted networks, disable remote administration, and avoid PPPoE credentials containing shell metacharacters where possible. No exploitation is confirmed in the wild, but given the elevated EPSS score, monitor Edimax advisories and treat WAN-reachable units as priority targets.

9.827% PoC
  • Edimax BR-6208AC V2 router firmware V2_1.02 (firmware 1.02 is the only version identified; other versions are not documented in the available data)
nichelikely on the order of a few thousand internet-exposed units or fewer (estimated, no reliable public install counts for this model)
CVE-2025-15257
+2 in the same advisory: …15256 …15258
A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03.

A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formRoute of the component Web-based Configuration Interface. The manipulation of the argument strIp/strMask/strGateway results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Edimax confirms this issue: "The product mentioned, EDIMAX BR-6208AC V2, has reached its End of Life (EOL) status. It is no longer supported or maintained by Edimax, and it is no longer available for purchase in the market. Consequently, there will be no further firmware updates or patches for this device. We recommend users upgrade to newer models for better security." This vulnerability only affects products that are no longer supported by the maintainer.

NVD description · AI analysis pending
5.5
group max
5% PoC
  • edimax br-6208ac firmware
CVE-2025-14910
A vulnerability was detected in Edimax BR-6208AC 1.02.

A vulnerability was detected in Edimax BR-6208AC 1.02. This impacts the function handle_retr of the component FTP Daemon Service. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used. Edimax confirms this issue: "This product is no longer available in the market and has been discontinued for five years. Consequently, Edimax no longer provides technical support, firmware updates, or security patches for this specific model. However, to ensure the safety of our remaining active users, we acknowledge this report and will take the following mitigation actions: (A) We will issue an official security advisory on our support website. (B) We will strongly advise users to disable the FTP service on this device to mitigate the reported risk, by which the product will still work for common use. (C) We will recommend users upgrade to newer, supported models." This vulnerability only affects products that are no longer supported by the maintainer.

NVD description · AI analysis pending
2.1<1% PoC
  • edimax br-6208ac firmware
CVE-2025-14094
+2 in the same advisory: …14093 …14092
Remote OS Command Injection in Edimax BR-6478AC V3 Router Web Interface

CVE-2025-14094 is an OS command injection flaw (CWE-77/CWE-78) in the sysCmd parameter processed by the formSysCmd handler (function sub_44CCE4) of the boa web server on the Edimax BR-6478AC V3 running firmware 1.0.15. A remote attacker can trigger it by sending a crafted request to /boafrm/formSysCmd with malicious content in the sysCmd argument; per the CVSS 4.0 vector, high privileges (administrator-level access to the web management interface) are required and no user interaction is needed. Successful exploitation lets the attacker execute arbitrary operating-system commands on the router, compromising the device's confidentiality, integrity, and availability (each rated low in the base score, though device-level control is the practical risk). Only Edimax BR-6478AC V3 deployments on the disclosed firmware version are confirmed affected, and the vendor was contacted early about the issue but did not respond in any way. A public proof-of-concept has been published on GitHub, EPSS assigns a 20.3% probability of exploitation within 30 days (97th percentile), and the flaw is not yet listed in CISA KEV.

Do: No fixed firmware version has been announced because the vendor did not respond to the disclosure, so verify your current firmware (1.0.15 is the confirmed affected version) and watch for an Edimax firmware update. Until a patch is available, avoid exposing the router's web management interface to the internet, restrict administrative access to trusted hosts, and use a strong, unique administrator password since exploitation requires admin privileges. Given the 20.3% EPSS score, treat this as a near-term exploitation risk for any internet-facing BR-6478AC V3 units and monitor them for signs of compromise.

2.020% PoC
  • Edimax BR-6478AC V3 router firmware 1.0.15 (confirmed affected; other versions not specified in the disclosure)
moderateon the order of 1,000-10,000 internet-exposed devices worldwide (estimate)
CVE-2025-56706
Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter in the openwrt_getConfig function.

Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter in the openwrt_getConfig function.

NVD description · AI analysis pending
8.02% PoC
  • edimax br-6473ax firmware
CVE-2025-34024
+1 in the same advisory: …34029
An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler.

An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters to achieve arbitrary command execution as the root user. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-14 UTC.

NVD description · AI analysis pending
9.44% PoC ×2
  • edimax ew-7438rpn mini firmware
CVE-2025-45857
EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.

EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.

NVD description · AI analysis pending
9.81% PoC
  • edimax cv-7428ns firmware
CVE-2025-22911
RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function.

RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function.

NVD description · AI analysis pending
5.6<1% PoC ×2
  • edimax re11s firmware
CVE-2025-28145
+3 in the same advisory: …28142 …28143 …28144
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafrm/formDiskF

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafrm/formDiskFormat.

NVD description · AI analysis pending
6.510% PoC ×2
  • edimax br-6478ac v3 firmware
CVE-2025-28146
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefot

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel

NVD description · AI analysis pending
9.811% PoC ×2
  • edimax br-6478ac v3 firmware
CVE-2025-1316
Unauthenticated OS Command Injection RCE in Edimax IC-7100 IP Camera

CVE-2025-1316 is an OS command injection flaw (CWE-78) in the Edimax IC-7100 IP camera that fails to properly neutralize requests it receives. Because the request handling is reachable over the network without authentication or user interaction (per the CVSS 4.0 vector), an unauthenticated attacker can send specially crafted requests to the device. Successful exploitation yields full remote code execution on the camera, with high impact on confidentiality, integrity, and availability of the device itself. Only deployments using the Edimax IC-7100 camera and its firmware are affected. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-19, and public reporting indicates Mirai-based botnets have been exploiting it since roughly a year before its disclosure, making it effectively a zero-day used to recruit cameras into botnets.

Do: Per the CISA KEV required action, apply mitigations per vendor instructions or discontinue use of the IC-7100 if mitigations are unavailable; check whether Edimax has released updated firmware and install it. In the meantime, reduce exposure by removing any port-forwarding or direct internet access to affected cameras, restricting management interfaces to trusted networks, and monitoring for Mirai-like scanning or traffic. Treat exploitation as likely given the high EPSS (74.5% in 30 days) and in-the-wild botnet use.

9.374% KEV
  • Edimax IC-7100 IP Camera firmware
moderateapproximately 1,000-10,000 internet-exposed devices (estimated)
CVE-2025-1612
A vulnerability was found in Edimax BR-6288ACL 1.30.

A vulnerability was found in Edimax BR-6288ACL 1.30. It has been declared as problematic. This vulnerability affects unknown code of the file wireless5g_basic.asp. The manipulation of the argument SSID leads to cross site scripting. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.1<1%
  • edimax br-6288acl firmware
CVE-2024-48419
+4 in the same advisory: …48420 …48416 …48418 …48417
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead.

Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an attacker with access to the web interface to inject and execute arbitrary shell commands, with "root" privileges.

NVD description · AI analysis pending
8.8
group max
5% PoC
  • edimax br-6476ac firmware
CVE-2025-22905
RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.

RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.

NVD description · AI analysis pending
9.85% PoC
  • edimax re11s firmware
CVE-2024-7616
A vulnerability was found in Edimax IC-6220DC and IC-5150W up to 3.06.

A vulnerability was found in Edimax IC-6220DC and IC-5150W up to 3.06. It has been rated as critical. Affected by this issue is the function cgiFormString of the file ipcam_cgi. The manipulation of the argument host leads to command injection. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.15%
  • edimax ic-6220dc firmware
  • edimax ic-5150w firmware
CVE-2023-49351
A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite other values located

A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite other values located on the stack due to an incorrect use of the strcpy() function.

NVD description · AI analysis pending
9.8<1%
  • edimax br-6478ac firmware
CVE-2023-33722
EDIMAX BR-6288ACL v1.12 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the pppUserName parameter.

EDIMAX BR-6288ACL v1.12 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the pppUserName parameter.

NVD description · AI analysis pending
8.82% PoC
  • edimax br-6288acl firmware
CVE-2023-31986
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN function in /bin

A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN function in /bin/webs without any limitations.

NVD description · AI analysis pending
9.88% PoC
  • edimax br-6428ns firmware
CVE-2023-31983
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/web

A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/webs without any limitations.

NVD description · AI analysis pending
9.825% PoC
  • edimax br-6428ns firmware