Vulnerabilities (CVE)

Filtered by vendor Edimax Subscribe
Total 66 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-22916 1 Edimax 2 Re11s, Re11s Firmware 2026-07-05 N/A 9.8 CRITICAL
RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.
CVE-2025-22912 1 Edimax 2 Re11s, Re11s Firmware 2026-07-05 N/A 9.8 CRITICAL
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
CVE-2025-22907 1 Edimax 2 Re11s, Re11s Firmware 2026-07-05 N/A 9.8 CRITICAL
RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.
CVE-2025-22906 1 Edimax 2 Re11s, Re11s Firmware 2026-07-05 N/A 9.8 CRITICAL
RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.
CVE-2025-22905 1 Edimax 2 Re11s, Re11s Firmware 2026-07-05 N/A 9.8 CRITICAL
RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.
CVE-2025-22904 1 Edimax 2 Re11s, Re11s Firmware 2026-07-05 N/A 9.8 CRITICAL
RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.
CVE-2024-48420 1 Edimax 2 Br-6476ac, Br-6476ac Firmware 2026-07-05 N/A 8.8 HIGH
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/getWifiBasic.
CVE-2024-48419 1 Edimax 2 Br-6476ac, Br-6476ac Firmware 2026-07-05 N/A 8.8 HIGH
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an attacker with access to the web interface to inject and execute arbitrary shell commands, with "root" privileges.
CVE-2024-48418 1 Edimax 2 Br-6476ac, Br-6476ac Firmware 2026-07-05 N/A 8.8 HIGH
In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.
CVE-2024-48417 1 Edimax 2 Br-6476ac, Br-6476ac Firmware 2026-07-05 N/A 5.2 MEDIUM
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Cross Site Scripting (XSS) in : /bin/goahead via /goform/setStaticRoute, /goform/fromSetFilterUrlFilter, and /goform/fromSetFilterClientFilter.
CVE-2024-48416 1 Edimax 2 Br-6476ac, Br-6476ac Firmware 2026-07-05 N/A 8.8 HIGH
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/fromSetLanDhcpsClientbinding.
CVE-2026-32842 1 Edimax 2 Gs-5008pl, Gs-5008pl Firmware 2026-06-17 N/A 6.5 MEDIUM
Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows attackers to obtain administrator credentials by accessing configuration backup files. Attackers can download the config.bin file through fupload.cgi to extract plaintext username and password fields for unauthorized administrative access.
CVE-2026-32841 1 Edimax 2 Gs-5008pl, Gs-5008pl Firmware 2026-06-17 N/A 8.1 HIGH
Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the global authentication flag mechanism to gain administrative access without credentials after any user authenticates, enabling unauthorized password changes, firmware uploads, and configuration modifications.
CVE-2026-32840 1 Edimax 2 Gs-5008pl, Gs-5008pl Firmware 2026-06-17 N/A 5.4 MEDIUM
Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_name_set.cgi script that allows attackers to inject arbitrary script code by manipulating the sysName parameter. Attackers can send a crafted POST request with malicious script payload that executes when management pages including system_data.js are viewed by administrators.
CVE-2026-32839 1 Edimax 2 Gs-5008pl, Gs-5008pl Firmware 2026-06-17 N/A 4.3 MEDIUM
Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauthorized administrative actions by inducing logged-in administrators to visit malicious pages. Attackers can exploit the lack of anti-CSRF tokens and request validation to change passwords, upload firmware, reboot the device, perform factory resets, or modify network configurations.
CVE-2026-32838 1 Edimax 2 Gs-5008pl, Gs-5008pl Firmware 2026-06-17 N/A 7.5 HIGH
Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. Attackers on the same network can intercept management traffic to capture administrator credentials and sensitive configuration data.
CVE-2026-1972 1 Edimax 2 Br-6208ac, Br-6208ac Firmware 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Performing a manipulation of the argument Username/Password results in use of default credentials. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor confirms that the affected product is end-of-life. They confirm that they "will issue a consolidated Security Advisory on our official support website." This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-1971 1 Edimax 2 Br-6288acl, Br-6288acl Firmware 2026-06-17 3.3 LOW 2.4 LOW
A vulnerability has been found in Edimax BR-6288ACL up to 1.12. Impacted is the function wiz_WISP24gmanual of the file wiz_WISP24gmanual.asp. Such manipulation of the argument manualssid leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor confirms that the affected product is end-of-life. They confirm that they "will issue a consolidated Security Advisory on our official support website." This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-1970 1 Edimax 2 Br-6258n, Br-6258n Firmware 2026-06-17 4.0 MEDIUM 3.5 LOW
A flaw has been found in Edimax BR-6258n up to 1.18. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup. This manipulation of the argument submit-url causes open redirect. The attack can be initiated remotely. The exploit has been published and may be used. The vendor confirms that the affected product is end-of-life. They confirm that they "will issue a consolidated Security Advisory on our official support website." This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-70161 1 Edimax 2 Br-6208ac, Br-6208ac Firmware 2026-06-17 N/A 9.8 CRITICAL
EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbitrary code execution.