CVE-2026-12809: fallo de gravedad media en Edimax BR-6478AC V2
Edimax BR-6478AC V2 POST Request wiz_5in1_redirect command injection
Publicada el · Actualizada el
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3epss 2.0%
probabilidad de explotación
2.0%top 20% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the component POST Request Handler. Such manipulation of the argument newpass leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
Edimax · BR-6478AC V2PoCs públicas encontradas — 1
cve_referencelavender-bicycle-a5a.notion.site/EDIMAX-BR6478ACV2-wiz_5in1_redirect-34b53a41781f80408b3fca68a24f6028?source=copy_linkno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — Edimax BR-6478AC V2
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-12810MEDIUMEdimax BR-6478AC V2 POST Request mp command injectionEPSS 2.0%CVE-2026-12808MEDIUMEdimax BR-6478AC V2 POST Request stainfo command injectionEPSS 2.0%CVE-2026-12807MEDIUMEdimax BR-6478AC V2 POST Request setWAN command injectionEPSS 2.0%CVE-2026-12806HIGHEdimax BR-6478AC V2 POST Request formWlSiteSurvey buffer overflowEPSS 0.8%