In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.
CVSS
No CVSS.
References
Link | Resource |
---|---|
http://edimax.com | Product |
https://github.com/SpikeReply/advisories/blob/c271ddb997bc0263274118acc380bc71ce9c316b/cve/edimax/cve-2024-48418.md | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
28 May 2025, 17:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/SpikeReply/advisories/blob/c271ddb997bc0263274118acc380bc71ce9c316b/cve/edimax/cve-2024-48418.md - Exploit, Third Party Advisory | |
References | () http://edimax.com - Product | |
CPE | cpe:2.3:o:edimax:br-6476ac_firmware:1.06:*:*:*:*:*:*:* cpe:2.3:h:edimax:br-6476ac:-:*:*:*:*:*:*:* |
|
First Time |
Edimax br-6476ac
Edimax Edimax br-6476ac Firmware |
27 Jan 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-27 17:15
Updated : 2025-05-28 17:53
NVD link : CVE-2024-48418
Mitre link : CVE-2024-48418
JSON object : View
Products Affected
edimax
- br-6476ac
- br-6476ac_firmware
CWE
No CWE.