High severity8.8NVD Advisory· Published Jan 27, 2025· Updated Jul 5, 2026
CVE-2024-48419
CVE-2024-48419
Description
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an attacker with access to the web interface to inject and execute arbitrary shell commands, with "root" privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:edimax:br-6476ac_firmware:1.06:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/SpikeReply/advisories/blob/c271ddb997bc0263274118acc380bc71ce9c316b/cve/edimax/cve-2024-48419.mdnvdExploitThird Party Advisory
News mentions
2- Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell CommandsCyber Security News · Aug 5, 2026
- Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)SANS Internet Storm Center · Aug 4, 2026