OS Command Injection Vulnerability in Edimax EW-7478APC by Edimax
CVE-2026-13560
Key Information:
- Vendor
Edimax
- Status
- Vendor
- CVE Published:
- 29 June 2026
Badges
What is CVE-2026-13560?
A security vulnerability has been identified in the Edimax EW-7478APC version 1.04, specifically within the formAccept function of the POST Request Handler. This flaw allows remote attackers to manipulate the submit-url parameter, leading to potential OS command injection. This vulnerability has been publicly disclosed, and despite attempts to alert the vendor, there has been no response. Users of this device are advised to take necessary precautions and monitor for any malicious activity.
Affected Version(s)
EW-7478APC 1.04
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
