OS Command Injection Vulnerability in Edimax BR-6214K Router
CVE-2026-82703
Key Information:
Badges
What is CVE-2026-82703?
A security vulnerability has been identified in the Edimax BR-6214K router, specifically affecting the asp_setPing endpoint within the file www/ping.asp. This flaw allows an attacker to manipulate the pingstr argument, enabling remote OS command injection. The exploitation of this vulnerability poses a significant risk, as it provides unauthorized access to the router's operating system, potentially leading to further attacks. Despite early notification to the vendor, no response has been received regarding this critical issue.
Affected Version(s)
BR-6214K 1.40
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
