OS Command Injection Vulnerability in Edimax EW-7438RPn Router
CVE-2026-9347
Key Information:
- Vendor
Edimax
- Status
- Vendor
- CVE Published:
- 24 May 2026
Badges
What is CVE-2026-9347?
A vulnerability has been discovered in the Edimax EW-7438RPn router affecting versions up to 1.31. The issue resides in the function formWizSurvey located in the /goform/formWizSurvey file, where improper handling of the arguments ip, mask, and gateway can lead to OS command injection. This flaw allows an attacker to execute arbitrary commands on the device remotely. The exploit has been publicly disclosed, raising serious security concerns, particularly since the vendor has not responded to initial notifications regarding the issue.
Affected Version(s)
EW-7438RPn 1.0
EW-7438RPn 1.1
EW-7438RPn 1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
