Command Injection Vulnerability in Edimax AC1200 Dual-Band Gigabit Router
CVE-2025-28146
9.8CRITICAL
What is CVE-2025-28146?
A command injection vulnerability has been identified in the Edimax AC1200 Wave 2 Dual-Band Gigabit Router model BR-6478AC V3, specifically in the fota_url parameter within the /boafrm/formLtefotaUpgradeQuectel interface. This flaw could allow an unauthenticated attacker to execute arbitrary commands, potentially leading to unauthorized access and control over the device, thus compromising network security.