Command Injection Vulnerability in Edimax AC1200 Wave 2 Dual-Band Gigabit Router
CVE-2025-28145

6.5MEDIUM

Key Information:

Vendor

Edimax

Vendor
CVE Published:
15 April 2025

What is CVE-2025-28145?

The Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 version 1.0.15 is susceptible to a command injection vulnerability. This issue arises when an attacker can exploit the partition parameter in the /boafrm/formDiskFormat interface, potentially leading to unauthorized command execution on the router. Such vulnerabilities can compromise network integrity and provide attackers with the means to manipulate or compromise devices within a secured network environment.

References

EPSS Score

7% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.