Edimax
Products
54- 29 CVEs
- 24 CVEs
- 14 CVEs
- 12 CVEs
- 11 CVEs
- 10 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- 8 CVEs
- 7 CVEs
- 5 CVEs
- 5 CVEs
- 5 CVEs
- 5 CVEs
- 5 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 4 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 3 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- View all 54 products →
Recent CVEs
149| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-1316 | Cri | 0.81 | 9.8 | 0.74 | KEV | Mar 5, 2025 | Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device | |
| CVE-2025-70161 | Cri | 0.66 | 9.8 | 0.27 | Jan 9, 2026 | EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName… | ||
| CVE-2023-31983 | Cri | 0.66 | 9.8 | 0.25 | May 12, 2023 | A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/webs without any limitations. | ||
| CVE-2026-19961 | Cri | 0.64 | 9.9 | 0.01 | Aug 16, 2026 | A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is… | ||
| CVE-2026-19959 | Cri | 0.64 | 9.9 | 0.01 | Aug 16, 2026 | A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The… | ||
| CVE-2020-37125 | Cri | 0.64 | 9.8 | 0.07 | Feb 5, 2026 | Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection… | ||
| CVE-2025-45857 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2025 | EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function. | ||
| CVE-2025-28146 | Cri | 0.64 | 9.8 | 0.11 | Apr 4, 2025 | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel | ||
| CVE-2025-22916 | Cri | 0.64 | 9.8 | 0.01 | Jan 16, 2025 | RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function. | ||
| CVE-2025-22913 | Cri | 0.64 | 9.8 | 0.01 | Jan 16, 2025 | RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function. | ||
| CVE-2025-22912 | Cri | 0.64 | 9.8 | 0.02 | Jan 16, 2025 | RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept. | ||
| CVE-2025-22907 | Cri | 0.64 | 9.8 | 0.01 | Jan 16, 2025 | RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function. | ||
| CVE-2025-22906 | Cri | 0.64 | 9.8 | 0.02 | Jan 16, 2025 | RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN. | ||
| CVE-2025-22905 | Cri | 0.64 | 9.8 | 0.05 | Jan 16, 2025 | RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp. | ||
| CVE-2025-22904 | Cri | 0.64 | 9.8 | 0.01 | Jan 16, 2025 | RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function. | ||
| CVE-2023-49351 | Cri | 0.64 | 9.8 | 0.01 | Jan 16, 2024 | A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite other values located on the stack due to an incorrect use of the strcpy() function. | ||
| CVE-2023-31986 | Cri | 0.64 | 9.8 | 0.08 | May 15, 2023 | A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN function in /bin/webs without any limitations. | ||
| CVE-2023-31985 | Cri | 0.64 | 9.8 | 0.08 | May 12, 2023 | A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the formAccept function in /bin/webs without any limitations. | ||
| CVE-2021-40597 | Cri | 0.64 | 9.8 | 0.02 | Jun 29, 2022 | The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password. | ||
| CVE-2020-26762 | Cri | 0.64 | 9.8 | 0.02 | Dec 1, 2020 | A stack-based buffer-overflow exists in Edimax IP-Camera IC-3116W (v3.06) and IC-3140W (v3.07), which allows an unauthenticated, unauthorized attacker to perform remote-code-execution due to a crafted GET-Request. The overflow occurs in binary ipcam_cgi due to a missing type… |
- risk 0.81cvss 9.8epss 0.74
Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device
- risk 0.66cvss 9.8epss 0.27
EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName…
- risk 0.66cvss 9.8epss 0.25
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/webs without any limitations.
- risk 0.64cvss 9.9epss 0.01
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is…
- risk 0.64cvss 9.9epss 0.01
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The…
- risk 0.64cvss 9.8epss 0.07
Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection…
- risk 0.64cvss 9.8epss 0.01
EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.
- risk 0.64cvss 9.8epss 0.11
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel
- risk 0.64cvss 9.8epss 0.01
RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.
- risk 0.64cvss 9.8epss 0.01
RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function.
- risk 0.64cvss 9.8epss 0.02
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
- risk 0.64cvss 9.8epss 0.01
RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.
- risk 0.64cvss 9.8epss 0.02
RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.
- risk 0.64cvss 9.8epss 0.05
RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.
- risk 0.64cvss 9.8epss 0.01
RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.
- risk 0.64cvss 9.8epss 0.01
A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite other values located on the stack due to an incorrect use of the strcpy() function.
- risk 0.64cvss 9.8epss 0.08
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN function in /bin/webs without any limitations.
- risk 0.64cvss 9.8epss 0.08
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the formAccept function in /bin/webs without any limitations.
- risk 0.64cvss 9.8epss 0.02
The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.
- risk 0.64cvss 9.8epss 0.02
A stack-based buffer-overflow exists in Edimax IP-Camera IC-3116W (v3.06) and IC-3140W (v3.07), which allows an unauthenticated, unauthorized attacker to perform remote-code-execution due to a crafted GET-Request. The overflow occurs in binary ipcam_cgi due to a missing type…