Command Injection Vulnerability in Edimax AC1200 Wave 2 Dual-Band Gigabit Router
CVE-2025-28143

6.5MEDIUM

Key Information:

Vendor

Edimax

Vendor
CVE Published:
15 April 2025

What is CVE-2025-28143?

A command injection vulnerability has been identified in the Edimax AC1200 Wave 2 Dual-Band Gigabit Router (model BR-6478AC), specifically in version V3_1.0.15. This vulnerability allows an attacker to execute arbitrary commands on the router by sending crafted requests to the system, particularly through the 'groupname' parameter at the /boafrm/formDiskCreateGroup endpoint. Successful exploitation could lead to unauthorized access and control over the device, highlighting a critical need for users to update their firmware or implement mitigative measures.

References

EPSS Score

7% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.