Command Injection Vulnerability in Edimax EW-7438RPn Device
CVE-2026-9363
Key Information:
- Vendor
Edimax
- Status
- Vendor
- CVE Published:
- 24 May 2026
Badges
What is CVE-2026-9363?
A command injection vulnerability exists in the Edimax EW-7438RPn device, specifically within the function formEZCHNwlanSetup of the POST Request Handler component. This flaw can be exploited through the manipulation of the argument method, allowing for unauthorized remote command execution. The implications of this security issue are significant, especially since the exploit has been publicly disclosed. Notably, attempts to notify the vendor about the vulnerability went unanswered, leaving users exposed to potential attacks.
Affected Version(s)
EW-7438RPn 1.12
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
