Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-48419


Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an attacker with access to the web interface to inject and execute arbitrary shell commands, with "root" privileges.


Published

2025-01-27T17:15:16.053

Last Modified

2025-05-28T17:54:25.953

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System edimax br-6476ac_firmware 1.06 Yes
Hardware edimax br-6476ac - No

References