Description
A vulnerability was detected in Edimax BR-6228NC 1.22. Affected by this issue is the function mp of the file /goform/mp of the component POST Request Handler. The manipulation of the argument command results in command injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Problem types
Product status
Timeline
| 2026-05-17: | Advisory disclosed |
| 2026-05-17: | VulDB entry created |
| 2026-05-17: | VulDB entry last update |
Credits
wxhwxhwxh_tutu (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/364399 (VDB-364399 | Edimax BR-6228NC POST Request mp command injection)
vuldb.com/vuln/364399/cti (VDB-364399 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/811529 (Submit #811529 | EDIMAX BR6228NC BR-6228NCv2 (Version : v1.22) Command Injection)
lavender-bicycle-a5a.notion.site/...3ea24b9?source=copy_link