Command Injection Vulnerability in Edimax BR-6228NC Network Device
CVE-2026-8774
Key Information:
Badges
What is CVE-2026-8774?
A command injection vulnerability exists in the Edimax BR-6228NC router, specifically affecting the 'mp' function within the POST Request Handler at /goform/mp. Manipulating the 'command' argument allows attackers to execute arbitrary commands remotely. This exploitation could lead to unauthorized access and control over the device. The issue has been made public, and although the vendor was notified, there has been no response regarding a patch or mitigation measures. Users are advised to assess their security posture and apply any available updates while monitoring for potential exploits.
Affected Version(s)
BR-6228NC 1.22
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
