Edimax
Products: BR-6208AC · BR-6228NC · BR-6258n · BR-6288ACL · BR-6428NS · BR-6428nC · BR-6478AC · BR-6478AC V2 · BR-6478AC V3 · BR-6675nD · EW-7438RPn · IC-7100 IP Camera
40.6
Score
68
CVEs
1
Active
67
PoC
1
KEV
#78
Rank
Period:
Product:
| CVE ID | Published | CVSS | Exploit | KEV | AC | PR | Auto | Score(hover) | Affected Products | Description |
|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-12806 | 2026-06-21 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC V2 | A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. It is possible to initiate the attack remot |
| CVE-2026-12807 | 2026-06-21 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC V2 | A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Handler. The manipulation of the argument pppUserName/pptpUserName/L2TPUserName results in command injection. It is possible to launch the attack remotely. |
| CVE-2026-12808 | 2026-06-21 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC V2 | A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainfo of the component POST Request Handler. This manipulation of the argument interface causes command injection. The attack can be initiated remotely. The exploit has been publicly d |
| CVE-2026-12809 | 2026-06-21 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC V2 | A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the component POST Request Handler. Such manipulation of the argument newpass leads to command injection. The attack can be launched remotely. The exploit i |
| CVE-2026-12810 | 2026-06-21 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC V2 | A security flaw has been discovered in Edimax BR-6478AC V2 1.23. Affected by this vulnerability is the function mp of the file /goform/mp of the component POST Request Handler. Performing a manipulation of the argument command results in command injection. The attack may be initiated remotely. The e |
| CVE-2026-10163 | 2026-05-31 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC | A vulnerability has been found in Edimax BR-6478AC 1.23. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. The manipulation of the argument UserName/Password leads to buffer overflow. Remote exploitation of the attack is possible |
| CVE-2026-10164 | 2026-05-31 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC | A vulnerability was found in Edimax BR-6478AC 1.23. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. The manipulation of the argument ShareName/SelectName results in buffer overflow. The attack can be executed remotely. The exploit has b |
| CVE-2026-10165 | 2026-05-31 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC | A vulnerability was identified in Edimax BR-6478AC 1.23. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manipulation of the argument pppUserName leads to stack-based buffer overflow. The attack may be performed |
| CVE-2026-10166 | 2026-05-31 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC | A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. This manipulation of the argument rootAPmac causes command injection. The attack is possible to be carried out remotely. Th |
| CVE-2026-10125 | 2026-05-30 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC | A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. The manipulation of the argument pppUserName leads to stack-based buffer overflow. The attack can be initia |
| CVE-2026-10126 | 2026-05-30 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC | A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID results in buffer overflow. The attack can be launched remotely. The exploit has be |
| CVE-2026-10127 | 2026-05-30 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC | A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. This manipulation of the argument rootAPmac causes command injection. The attack may be initiated remotely. The exploit has be |
| CVE-2026-9423 | 2026-05-25 | 5.1v4.0 | POC | — | Low | High | no | 0.0 | BR-6675nD | A security flaw has been discovered in Edimax BR-6675nD 1.12. Impacted is the function mp of the file /goform/mp of the component POST Request Handler. Performing a manipulation of the argument command results in command injection. The attack may be initiated remotely. The exploit has been released |
| CVE-2026-9424 | 2026-05-25 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A weakness has been identified in Edimax EW-7438RPn 1.31. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component Content-Type Handler. Executing a manipulation of the argument ateFunc/ateGain/ateTxCount/ateChan/ateRate/ateMacID/e2pTxPower1/e2pTxPower2/e2pTxPo |
| CVE-2026-9425 | 2026-05-25 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The impacted element is the function formWlanMP of the file /goform/formWlanMP. The manipulation of the argument ateFunc/ateGain/ateTxCount/ateChan/ateRate/ateMacID/e2pTxPower1/e2pTxPower2/e2pTxPower3/e2pTxPower4/e2pTxPower5/e2pTx |
| CVE-2026-9426 | 2026-05-25 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A vulnerability was detected in Edimax EW-7438RPn 1.31. This affects the function formHwSet of the file /goform/formHwSet. The manipulation of the argument Anntena/Mcs/regDomain/nic0Addr/nic1Addr/wlanAddr/wanAddr/wlanSSID/wlanChan/initgain/txcck/txofdm/submit-url results in stack-based buffer overfl |
| CVE-2026-9427 | 2026-05-25 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A flaw has been found in Edimax EW-7438RPn 1.31. This impacts the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component webs. This manipulation of the argument selSSID/submit-url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The expl |
| CVE-2026-9439 | 2026-05-25 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6675nD | A vulnerability was determined in Edimax BR-6675nD 1.12. Affected is the function stainfo of the file /goform/stainfo. This manipulation of the argument interface causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. Th |
| CVE-2026-9440 | 2026-05-25 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC | A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of the file /goform/formAccept of the component POST Request Handler. Such manipulation of the argument submit-url leads to command injection. It is possible to launch the attack remote |
| CVE-2026-9441 | 2026-05-25 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC | A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. Performing a manipulation of the argument rootAPmac results in command injection. The attack can be initiated re |
| CVE-2026-9442 | 2026-05-25 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC | A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. Executing a manipulation of the argument selSSID can lead to buffer overflow. The attack can be launched remotely. The e |
| CVE-2026-9443 | 2026-05-25 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6478AC | A security vulnerability has been detected in Edimax BR-6478AC 1.23. This vulnerability affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. The manipulation of the argument L2TPUserName leads to buffer overflow. The attack may be initiated remo |
| CVE-2026-9459 | 2026-05-25 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A security flaw has been discovered in Edimax EW-7438RPn 1.31. This affects the function formConnectionSetting of the file /goform/formConnectionSetting. Performing a manipulation of the argument max_Conn/timeOut results in stack-based buffer overflow. It is possible to initiate the attack remotely. |
| CVE-2026-9460 | 2026-05-25 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A weakness has been identified in Edimax EW-7438RPn 1.31. This impacts the function formAccept of the file /goform/formAccept. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made availabl |
| CVE-2026-9461 | 2026-05-25 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A security vulnerability has been detected in Edimax EW-7438RPn 1.31. Affected is the function formRadius of the file /goform/formRadius. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed publicly an |
| CVE-2026-9462 | 2026-05-25 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A vulnerability was detected in Edimax EW-7438RPn 1.31. Affected by this vulnerability is the function formWpsProxyEnable of the file /goform/formWpsProxyEnable. The manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be launched remotely. The exploit is no |
| CVE-2026-9463 | 2026-05-25 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the function formLicence of the file /goform/formLicence. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. |
| CVE-2026-9479 | 2026-05-25 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of the file /goform/formLogout. The manipulation of the argument submit-url leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been |
| CVE-2026-9480 | 2026-05-25 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of the argument submit-url results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and ma |
| CVE-2026-9481 | 2026-05-25 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formStats of the file /goform/formStats. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was co |
| CVE-2026-9344 | 2026-05-24 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A security vulnerability has been detected in Edimax EW-7438RPn up to 1.31. The impacted element is an unknown function of the file /goform/formWpsStart of the component webs. Such manipulation of the argument pinCode/wlan-url leads to stack-based buffer overflow. The attack can be executed remotely |
| CVE-2026-9345 | 2026-05-24 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A vulnerability was detected in Edimax EW-7438RPn up to 1.31. This affects the function formWizSurvey of the file /goform/formWizSurvey of the component webs. Performing a manipulation of the argument ssid/manualssid/ip/mask/gateway results in buffer overflow. The attack is possible to be carried ou |
| CVE-2026-9346 | 2026-05-24 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A flaw has been found in Edimax EW-7438RPn up to 1.31. This impacts the function formWirelessTbl of the file /goform/formWirelessTbl of the component webs. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been p |
| CVE-2026-9347 | 2026-05-24 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A vulnerability has been found in Edimax EW-7438RPn up to 1.31. Affected is the function formWizSurvey of the file /goform/formWizSurvey of the component webs. The manipulation of the argument ip/mask/gateway leads to os command injection. It is possible to initiate the attack remotely. The exploit |
| CVE-2026-9348 | 2026-05-24 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A vulnerability was found in Edimax EW-7438RPn up to 1.31. Affected by this vulnerability is an unknown functionality of the file /goform/mp of the component webs. The manipulation of the argument webs results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit |
| CVE-2026-9359 | 2026-05-24 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A vulnerability was identified in Edimax EW-7438RPn 1.28a. Affected by this vulnerability is the function formHwSet of the file /goform/formHwSet of the component POST Request Handler. The manipulation of the argument Anntena/Mcs/regDomain/nic0Addr/nic1Addr/wlanAddr/wanAddr/wlanSSID/wlanChan/comd/in |
| CVE-2026-9360 | 2026-05-24 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A security flaw has been discovered in Edimax EW-7438RPn 1.28a. Affected by this issue is the function formwlencrypt24g of the file /goform/formwlencrypt24g of the component POST Request Handler. The manipulation of the argument key1 results in buffer overflow. The attack can be launched remotely. T |
| CVE-2026-9361 | 2026-05-24 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A weakness has been identified in Edimax EW-7438RPn 1.12. This affects the function formAccept of the file /goform/formAccep of the component POST Request Handler. This manipulation of the argument submit-url causes command injection. The attack may be initiated remotely. The exploit has been made a |
| CVE-2026-9362 | 2026-05-24 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A security vulnerability has been detected in Edimax EW-7438RPn 1.12. This vulnerability affects the function formConnectionSetting of the file /goform/formConnectionSetting of the component Setting Handler. Such manipulation of the argument max_Conn/timeOut leads to command injection. The attack ma |
| CVE-2026-9363 | 2026-05-24 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A vulnerability was detected in Edimax EW-7438RPn 1.12. This issue affects the function formEZCHNwlanSetup of the file /goform/formEZCHNwlanSetu of the component POST Request Handler. Performing a manipulation of the argument method results in command injection. Remote exploitation of the attack is |
| CVE-2026-9378 | 2026-05-24 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6675nD | A security flaw has been discovered in Edimax BR-6675nD 1.12. This affects the function formHwSet of the file /goform/formHwSet of the component POST Request Handler. The manipulation of the argument regDomain/ABandregDomain/nic0Addr/nic1Addr/wlanAddr/inicAddr results in command injection. It is pos |
| CVE-2026-9379 | 2026-05-24 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6675nD | A weakness has been identified in Edimax BR-6675nD 1.12. This impacts the function formWpsStart of the file /goform/formWpsStart of the component POST Request Handler. This manipulation of the argument pinCode causes command injection. The attack can be initiated remotely. The exploit has been made |
| CVE-2026-9380 | 2026-05-24 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6675nD | A security vulnerability has been detected in Edimax BR-6675nD 1.12. Affected is the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such manipulation of the argument L2TPUserName leads to buffer overflow. The attack can be launched remotely. The explo |
| CVE-2026-9381 | 2026-05-24 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6675nD | A vulnerability was detected in Edimax BR-6675nD 1.12. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. Performing a manipulation of the argument pppUserName results in buffer overflow. The attack may be initiated |
| CVE-2026-9399 | 2026-05-24 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6675nD | A vulnerability was detected in Edimax BR-6675nD 1.12. This vulnerability affects the function formsetPPPoE of the file /goform/formsetPPPoE of the component POST Request Handler. Performing a manipulation of the argument pppUserName results in buffer overflow. It is possible to initiate the attack |
| CVE-2026-9400 | 2026-05-24 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6675nD | A flaw has been found in Edimax BR-6675nD 1.12. This issue affects the function formUSBStorage of the file /goform/formUSBStorage of the component POST Request Handler. Executing a manipulation of the argument sub_dir can lead to command injection. It is possible to launch the attack remotely. The e |
| CVE-2026-9401 | 2026-05-24 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6675nD | A vulnerability has been found in Edimax BR-6675nD 1.12. Impacted is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. The manipulation of the argument pppUserName leads to buffer overflow. The attack can be initiated remotely. The exploit ha |
| CVE-2026-9402 | 2026-05-24 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6675nD | A vulnerability was found in Edimax BR-6675nD 1.12. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component POST Request Handler. The manipulation of the argument ateFunc/ateGain/ateRate/ateChan/ateTxCount/e2pTx2Power1/e2pTx2Power2/e2pTx2Power3/e2pTx2Power4/e2 |
| CVE-2026-9403 | 2026-05-24 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6675nD | A vulnerability was determined in Edimax BR-6675nD 1.12. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. This manipulation of the argument selSSID causes buffer overflow. The attack may be initiated remotely. The explo |
| CVE-2026-9294 | 2026-05-23 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6428NS | A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manipulation of the argument pppUserName leads to buffer overflow. It is possible to launch the attack rem |
| CVE-2026-9296 | 2026-05-23 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6428NS | A weakness has been identified in Edimax BR-6428NS 1.10. This impacts the function system of the file /goform/formWlanM of the component POST Request Handler. Executing a manipulation of the argument ateFunc/ateGain/ateTxCount/ateChan/ateRate/ateMacID/e2pTxPower1/e2pTxPower2/e2pTxPower3/e2pTxPower4/ |
| CVE-2026-9297 | 2026-05-23 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6428NS | A security vulnerability has been detected in Edimax BR-6428NS 1.10. Affected is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. The manipulation of the argument repeaterSSID leads to command injection. The attack may be initiated remotely. The exploit |
| CVE-2026-9343 | 2026-05-23 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | EW-7438RPn | A weakness has been identified in Edimax EW-7438RPn up to 1.31. The affected element is the function formWpsStart of the file /goform/formWpsStart of the component webs. This manipulation of the argument pinCode causes os command injection. Remote exploitation of the attack is possible. The exploit |
| CVE-2026-8774 | 2026-05-18 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6228NC | A vulnerability was detected in Edimax BR-6228NC 1.22. Affected by this issue is the function mp of the file /goform/mp of the component POST Request Handler. The manipulation of the argument command results in command injection. The attack may be performed from remote. The exploit is now public and |
| CVE-2026-8775 | 2026-05-18 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6428NS | A flaw has been found in Edimax BR-6428NS 1.10. This affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. This manipulation of the argument L2TPUserName causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been |
| CVE-2026-8776 | 2026-05-18 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6428NS | A vulnerability has been found in Edimax BR-6428NS 1.10. This vulnerability affects the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Request Handler. Such manipulation of the argument pptpUserName leads to buffer overflow. It is possible to launch the attack remotel |
| CVE-2026-8777 | 2026-05-18 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6428NS | A vulnerability was found in Edimax BR-6428NS 1.10. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. Performing a manipulation of the argument stadrv_ssid results in command injection. The attack can be initiated remotely. The |
| CVE-2026-7682 | 2026-05-03 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6208AC | A security flaw has been discovered in Edimax BR-6208AC 1.02. The impacted element is the function setWAN of the file /goform/setWAN of the component L2TP Mode. The manipulation of the argument L2TPUserName results in command injection. It is possible to launch the attack remotely. The exploit has b |
| CVE-2026-7683 | 2026-05-03 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6428nC | A weakness has been identified in Edimax BR-6428nC up to 1.16. This affects an unknown function of the file /goform/setWAN of the component Web Interface. This manipulation of the argument pppUserName/pptpUserName causes command injection. The attack can be initiated remotely. The exploit has been m |
| CVE-2026-7684 | 2026-05-03 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6428nC | A security vulnerability has been detected in Edimax BR-6428nC up to 1.16. This impacts an unknown function of the file /goform/setWAN. Such manipulation of the argument pptpDfGateway leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be u |
| CVE-2026-7685 | 2026-05-03 | 8.7v4.0 | POC | — | Low | Low | no | 0.0 | BR-6208AC | A vulnerability was detected in Edimax BR-6208AC up to 1.02. Affected is an unknown function of the file /goform/setWAN. Performing a manipulation of the argument pptpDfGateway results in buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used. The vendor wa |
| CVE-2026-1972 | 2026-02-06 | 6.9v4.0 | POC | — | Low | None | YES | 0.0 | BR-6208AC | A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Performing a manipulation of the argument Username/Password results in use of default credentials. The attack may be initiated remotely. The exploit has been made public and could be used |
| CVE-2025-15256 | 2025-12-30 | 6.9v4.0 | POC | — | Low | None | YES | 0.0 | BR-6208AC | A vulnerability was identified in Edimax BR-6208AC 1.02/1.03. Affected is the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component Web-based Configuration Interface. The manipulation of the argument rootAPmac leads to command injection. Remote exploitation of the attack is p |
| CVE-2025-14910 | 2025-12-19 | 5.3v4.0 | POC | — | Low | Low | no | 0.0 | BR-6208AC | A vulnerability was detected in Edimax BR-6208AC 1.02. This impacts the function handle_retr of the component FTP Daemon Service. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used. Edimax confirms this issue: "This product is n |
| CVE-2025-14092 | 2025-12-05 | 5.1v4.0 | POC | — | Low | High | no | 0.0 | BR-6478AC V3 | A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. This issue affects the function sub_416898 of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed p |
| CVE-2025-14093 | 2025-12-05 | 5.1v4.0 | POC | — | Low | High | no | 0.0 | BR-6478AC V3 | A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/formTracerouteDiagnosticRun. The manipulation of the argument host results in os command injection. The attack can be launched remotely. The exploit is now public and may be used. The |
| CVE-2025-14094 | 2025-12-05 | 5.1v4.0 | POC | — | Low | High | no | 0.0 | BR-6478AC V3 | A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm/formSysCmd. This manipulation of the argument sysCmd causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used. The vendor |
| CVE-2025-1316 | 2025-03-04 | 9.3v4.0 | ACTIVE | Low | None | YES | 40.6 | IC-7100 IP Camera | Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device |
Each CVE: 10 pts base (Active only), boosted by:
KEV×2.0AC: Low×1.2PR: None×1.3PR: Low×1.1Auto×1.3