VYPR
Vendor

Edimax

Products
53
CVEs
140
Across products
198
Status
Private

Products

53
View all 53 products →

Recent CVEs

140
View all 140 CVEs →
  • CVE-2025-1316CriKEVMar 5, 2025
    risk 0.81cvss 9.8epss 0.73

    Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device

  • CVE-2025-70161CriJan 9, 2026
    risk 0.66cvss 9.8epss 0.24

    EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName…

  • CVE-2023-31983CriMay 12, 2023
    risk 0.66cvss 9.8epss 0.25

    A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/webs without any limitations.

  • CVE-2020-37125CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.06

    Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection…

  • CVE-2025-45857CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.01

    EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.

  • CVE-2025-28146CriApr 4, 2025
    risk 0.64cvss 9.8epss 0.11

    Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel

  • CVE-2025-22916CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.

  • CVE-2025-22913CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function.

  • CVE-2025-22912CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.02

    RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.

  • CVE-2025-22907CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.

  • CVE-2025-22906CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.02

    RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.

  • CVE-2025-22905CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.05

    RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.

  • CVE-2025-22904CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.

  • CVE-2023-49351CriJan 16, 2024
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite other values located on the stack due to an incorrect use of the strcpy() function.

  • CVE-2023-31986CriMay 15, 2023
    risk 0.64cvss 9.8epss 0.08

    A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN function in /bin/webs without any limitations.

  • CVE-2023-31985CriMay 12, 2023
    risk 0.64cvss 9.8epss 0.08

    A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the formAccept function in /bin/webs without any limitations.

  • CVE-2021-40597CriJun 29, 2022
    risk 0.64cvss 9.8epss 0.02

    The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.

  • CVE-2020-26762CriDec 1, 2020
    risk 0.64cvss 9.8epss 0.02

    A stack-based buffer-overflow exists in Edimax IP-Camera IC-3116W (v3.06) and IC-3140W (v3.07), which allows an unauthenticated, unauthorized attacker to perform remote-code-execution due to a crafted GET-Request. The overflow occurs in binary ipcam_cgi due to a missing type…

  • CVE-2022-45768HigFeb 7, 2023
    risk 0.59cvss 8.8epss 0.29

    Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker to execute arbitrary code via the formWlanMP function.

  • CVE-2025-34024HigJun 20, 2025
    risk 0.58cvss 8.8epss 0.04

    An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using…