Critical severity9.8NVD Advisory· Published Jan 9, 2026· Updated Jun 17, 2026
CVE-2025-70161
CVE-2025-70161
Description
EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbitrary code execution.
Affected products
3cpe:2.3:o:edimax:br-6208ac_firmware:1.03:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:edimax:br-6208ac_firmware:1.03:*:*:*:*:*:*:*
- (no CPE)
- Range: 1.02
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.