A vulnerability was detected in Edimax EW-7478APC 1.04. The impacted element is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. The manipulation of the argument rootAPmac results in os command injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Mon, 29 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Jun 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in Edimax EW-7478APC 1.04. The impacted element is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. The manipulation of the argument rootAPmac results in os command injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Edimax EW-7478APC POST Request formiNICbasic os command injection | |
| First Time appeared |
Edimax
Edimax ew-7478apc |
|
| Weaknesses | CWE-77 CWE-78 |
|
| CPEs | cpe:2.3:a:edimax:ew-7478apc:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Edimax
Edimax ew-7478apc |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-06-29T11:00:17.712Z
Updated: 2026-06-29T12:48:39.114Z
Reserved: 2026-06-28T16:12:50.577Z
Link: CVE-2026-13561
Updated: 2026-06-29T12:48:32.759Z
No data.
No data.