VYPR
Vendor

Edimax

Products
54
CVEs
149
Across products
205
Status
Private

Products

54
View all 54 products →

Recent CVEs

149
View all 149 CVEs →
  • CVE-2025-1316CriKEVMar 5, 2025
    risk 0.81cvss 9.8epss 0.74

    Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device

  • CVE-2025-70161CriJan 9, 2026
    risk 0.66cvss 9.8epss 0.27

    EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName…

  • CVE-2023-31983CriMay 12, 2023
    risk 0.66cvss 9.8epss 0.25

    A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/webs without any limitations.

  • CVE-2026-19961CriAug 16, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is…

  • CVE-2026-19959CriAug 16, 2026
    risk 0.64cvss 9.9epss 0.01

    A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The…

  • CVE-2020-37125CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.07

    Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection…

  • CVE-2025-45857CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.01

    EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.

  • CVE-2025-28146CriApr 4, 2025
    risk 0.64cvss 9.8epss 0.11

    Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel

  • CVE-2025-22916CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.

  • CVE-2025-22913CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function.

  • CVE-2025-22912CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.02

    RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.

  • CVE-2025-22907CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.

  • CVE-2025-22906CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.02

    RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.

  • CVE-2025-22905CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.05

    RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.

  • CVE-2025-22904CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.

  • CVE-2023-49351CriJan 16, 2024
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite other values located on the stack due to an incorrect use of the strcpy() function.

  • CVE-2023-31986CriMay 15, 2023
    risk 0.64cvss 9.8epss 0.08

    A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN function in /bin/webs without any limitations.

  • CVE-2023-31985CriMay 12, 2023
    risk 0.64cvss 9.8epss 0.08

    A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the formAccept function in /bin/webs without any limitations.

  • CVE-2021-40597CriJun 29, 2022
    risk 0.64cvss 9.8epss 0.02

    The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.

  • CVE-2020-26762CriDec 1, 2020
    risk 0.64cvss 9.8epss 0.02

    A stack-based buffer-overflow exists in Edimax IP-Camera IC-3116W (v3.06) and IC-3140W (v3.07), which allows an unauthenticated, unauthorized attacker to perform remote-code-execution due to a crafted GET-Request. The overflow occurs in binary ipcam_cgi due to a missing type…