CVE-2025-70161

EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbitrary code execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:edimax:br-6208ac_firmware:1.03:*:*:*:*:*:*:*
cpe:2.3:h:edimax:br-6208ac:2.0:*:*:*:*:*:*:*

History

17 Jun 2026, 10:03

Type Values Removed Values Added
Summary
  • (es) EDIMAX BR-6208AC V2_1.02 es vulnerable a la inyección de comandos. Esto surge porque el campo pppUserName se pasa directamente a un comando de shell a través de la función system() sin una sanitización adecuada. Un atacante puede explotar esto inyectando comandos maliciosos en el campo pppUserName, lo que permite la ejecución de código arbitrario.

22 Jan 2026, 20:45

Type Values Removed Values Added
First Time Edimax
Edimax br-6208ac Firmware
Edimax br-6208ac
CPE cpe:2.3:h:edimax:br-6208ac:2.0:*:*:*:*:*:*:*
cpe:2.3:o:edimax:br-6208ac_firmware:1.03:*:*:*:*:*:*:*
References () https://tzh00203.notion.site/EDIMAX-BR-6208AC-V2_1-02-Command-Injection-Vulnerability-in-Web-setWAN-handler-2d3b5c52018a80d7ae8dce2bf5e3294c?source=copy_link - () https://tzh00203.notion.site/EDIMAX-BR-6208AC-V2_1-02-Command-Injection-Vulnerability-in-Web-setWAN-handler-2d3b5c52018a80d7ae8dce2bf5e3294c?source=copy_link - Exploit, Third Party Advisory

12 Jan 2026, 17:15

Type Values Removed Values Added
CWE CWE-77
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

09 Jan 2026, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-09 17:15

Updated : 2026-06-17 10:03


NVD link : CVE-2025-70161

Mitre link : CVE-2025-70161

CVE.ORG link : CVE-2025-70161


JSON object : View

Products Affected

edimax

  • br-6208ac
  • br-6208ac_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')