Command Injection Vulnerability in Edimax EW-7438RPn Wi-Fi Range Extender
CVE-2026-9359
Key Information:
- Vendor
Edimax
- Status
- Vendor
- CVE Published:
- 24 May 2026
Badges
What is CVE-2026-9359?
A command injection vulnerability exists in the formHwSet function of the POST Request Handler in Edimax EW-7438RPn Mini Firmware version 1.28a. By manipulating specific parameters such as Anntena, Mcs, and various address entries, an attacker can execute arbitrary commands remotely. This exploit is publicly available and poses a significant risk due to its ease of exploitation. Despite early notification to the vendor concerning this security issue, there has been no response or mitigation offered.
Affected Version(s)
EW-7438RPn 1.28a
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
