Command Injection Vulnerability in Edimax AC1200 Wave 2 Dual-Band Gigabit Router
CVE-2025-28143
6.5MEDIUM
What is CVE-2025-28143?
A command injection vulnerability has been identified in the Edimax AC1200 Wave 2 Dual-Band Gigabit Router (model BR-6478AC), specifically in version V3_1.0.15. This vulnerability allows an attacker to execute arbitrary commands on the router by sending crafted requests to the system, particularly through the 'groupname' parameter at the /boafrm/formDiskCreateGroup endpoint. Successful exploitation could lead to unauthorized access and control over the device, highlighting a critical need for users to update their firmware or implement mitigative measures.
References
EPSS Score
7% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved