A command injection vulnerability exists in the Edimax BR-6428NS router firmware version 1.10. The vulnerability is located in the formStaDrvSetup function within the /goform/formStaDrvSetup endpoint, where the stadrv_ssid parameter in POST requests is not properly sanitized before being passed to system commands. This allows remote attackers with low privileges to inject arbitrary commands. The vulnerabi [truncated]
A buffer overflow vulnerability exists in the Edimax BR-6428NS router firmware version 1.10. The flaw resides in the `formPPTPSetup` function within the `/goform/formPPTPSetup` endpoint, where improper handling of the `pptpUserName` parameter in POST requests allows remote attackers to trigger memory corruption. The vulnerability carries a HIGH severity CVSS score of 7.4 and can be exploited remotely with [truncated]
A buffer overflow vulnerability exists in the Edimax BR-6428NS router firmware version 1.10. The flaw resides in the formL2TPSetup function within the /goform/formL2TPSetup endpoint, where improper handling of the L2TPUserName parameter in POST requests allows remote attackers to trigger memory corruption. The vulnerability is remotely exploitable without authentication requirements, with public exploit a [truncated]
CVE-2025-1316 is an OS command injection vulnerability affecting the Edimax IC-7100 IP Camera. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-19, which means it has been identified as actively exploited and should be treated as a high-priority remediation item. The CISA KEV entry sets a remediation due date of 2025-04-09 and directs organizations to apply vendor mitigations, follo [truncated]