EIP-2026-101689

PRE-CVE

Edimax EW-7206-APg and EW-7209APg - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101689. PoCs published by m-1-k-3.

AI-analyzed exploit summary This advisory details multiple vulnerabilities in Edimax EW-7206APg and EW-7209APg devices, including URL redirection, reflected/stored XSS, and HTTP header injection. The vulnerabilities stem from improper input validation in parameters like submit-url, wlan-url, DomainName, and ssid.

Description

Edimax EW-7206-APg and EW-7209APg - Multiple Vulnerabilities

Exploits (1)

exploitdb WRITEUP
by m-1-k-3 · textwebappshardware
https://www.exploit-db.com/exploits/24503

This advisory details multiple vulnerabilities in Edimax EW-7206APg and EW-7209APg devices, including URL redirection, reflected/stored XSS, and HTTP header injection. The vulnerabilities stem from improper input validation in parameters like submit-url, wlan-url, DomainName, and ssid.

Classification
Writeup 100%
Attack Type
Xss | Info Leak | Other
Complexity
Trivial
Reliability
Reliable
Target: Edimax EW-7206APg (v1.32, v1.33) and EW-7209APg (v1.21, v1.29)
Auth required
Prerequisites: Network access to the vulnerable device · For stored XSS, authentication or alternative methods to inject malicious input
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026