CVE-2026-9402: medium-severity vulnerability in Edimax BR-6675nD
Edimax BR-6675nD POST Request formWlanMP command injection
Published · Updated
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 2.4%
exploitation probability
2.4%top 17% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was found in Edimax BR-6675nD 1.12. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component POST Request Handler. The manipulation of the argument ateFunc/ateGain/ateRate/ateChan/ateTxCount/e2pTx2Power1/e2pTx2Power2/e2pTx2Power3/e2pTx2Power4/e2pTx2Power5/e2pTx2Power6/e2pTx2Power7/e2pTxPower1/e2pTxPower2/e2pTxPower3/e2pTxPower4/e2pTxPower5/e2pTxPower6/e2pTxPower7/ateTxFreqOffset/ateMode/ateMacID/ateBW/ateAntenna/e2pTxFreqOffset/e2pTxPwDeltaB/e2pTxPwDeltaG/e2pTxPwDeltaMix/readE2P/e2pTxPwDeltaN results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
Edimax · BR-6675nDpublic PoCs found — 1
cve_referencelavender-bicycle-a5a.notion.site/EDIMAX-BR-6675nD-formWlanMP-34b53a41781f8041aa2ecb4fa1927f59?source=copy_linkunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — Edimax BR-6675nD
In the same product, most dangerous first.
CVE-2026-9423MEDIUMEdimax BR-6675nD POST Request mp command injectionEPSS 3.4%CVE-2026-9439MEDIUMEdimax BR-6675nD stainfo command injectionEPSS 2.4%CVE-2026-9400MEDIUMEdimax BR-6675nD POST Request formUSBStorage command injectionEPSS 2.4%CVE-2026-9379MEDIUMEdimax BR-6675nD POST Request formWpsStart command injectionEPSS 2.4%CVE-2026-9378MEDIUMEdimax BR-6675nD POST Request formHwSet command injectionEPSS 2.4%CVE-2026-9403HIGHEdimax BR-6675nD POST Request formWlSiteSurvey buffer overflowEPSS 0.8%