Edimax Vulnerabilities and Affected Products
Vulnerabilities associated with BR-6478AC V2.
Products
Clear product- EW-7438RPn26 vulnerabilities
- BR-6675nD12 vulnerabilities
- BR-6478AC11 vulnerabilities
- EW-7478APC9 vulnerabilities
- BR-6208AC7 vulnerabilities
- BR-6428NS7 vulnerabilities
- BR-6478AC V25 vulnerabilities
- BR-6478AC V33 vulnerabilities
- BR-6288ACL2 vulnerabilities
- BR-6428nC2 vulnerabilities
- Edimax EW-7438RPn Mini2 vulnerabilities
- BR-6228NC1 vulnerability
- BR-6258n1 vulnerability
- IC-5150W1 vulnerability
- IC-6220DC1 vulnerability
- IC-7100 IP Camera1 vulnerability
- re11s_firmware1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-12810MEDIUM | Edimax BR-6478AC V2 POST Request mp command injectionA security flaw has been discovered in Edimax BR-6478AC V2 1.23. Affected by this vulnerability is the function mp of the file /goform/mp of the component POST Request Handler. Performing a manipulation of the argument command results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS5.3v4.0 | EPSS1.99% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12809MEDIUM | Edimax BR-6478AC V2 POST Request wiz_5in1_redirect command injectionA vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the component POST Request Handler. Such manipulation of the argument newpass leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS5.3v4.0 | EPSS1.99% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12808MEDIUM | Edimax BR-6478AC V2 POST Request stainfo command injectionA vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainfo of the component POST Request Handler. This manipulation of the argument interface causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS5.3v4.0 | EPSS1.99% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12807MEDIUM | Edimax BR-6478AC V2 POST Request setWAN command injectionA vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Handler. The manipulation of the argument pppUserName/pptpUserName/L2TPUserName results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS5.3v4.0 | EPSS1.99% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12806HIGH | Edimax BR-6478AC V2 POST Request formWlSiteSurvey buffer overflowA vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS8.7v4.0 | EPSS0.805% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |