CVE-2024-48418

In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:edimax:br-6476ac_firmware:1.06:*:*:*:*:*:*:*
cpe:2.3:h:edimax:br-6476ac:-:*:*:*:*:*:*:*

History

28 May 2025, 17:53

Type Values Removed Values Added
References () https://github.com/SpikeReply/advisories/blob/c271ddb997bc0263274118acc380bc71ce9c316b/cve/edimax/cve-2024-48418.md - () https://github.com/SpikeReply/advisories/blob/c271ddb997bc0263274118acc380bc71ce9c316b/cve/edimax/cve-2024-48418.md - Exploit, Third Party Advisory
References () http://edimax.com - () http://edimax.com - Product
CPE cpe:2.3:o:edimax:br-6476ac_firmware:1.06:*:*:*:*:*:*:*
cpe:2.3:h:edimax:br-6476ac:-:*:*:*:*:*:*:*
First Time Edimax br-6476ac
Edimax
Edimax br-6476ac Firmware

27 Jan 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-27 17:15

Updated : 2025-05-28 17:53


NVD link : CVE-2024-48418

Mitre link : CVE-2024-48418


JSON object : View

Products Affected

edimax

  • br-6476ac
  • br-6476ac_firmware
CWE

No CWE.