Description
Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection payloads to download and execute malicious scripts on the device.
Problem types
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Credits
Wadeek
References
www.exploit-db.com/exploits/48318 (ExploitDB-48318)
www.edimax.com/...i-fi_range_extenders_n300/ew-7438rpn_mini/ (Edimax EW-7438RPn Mini Product Page)
www.vulncheck.com/...ology-ew-rpn-mini-remote-code-execution (VulnCheck Advisory: Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution)