Description

In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.

INFO

Published Date :

2025-01-27T00:00:00.000Z

Last Modified :

2025-01-28T19:44:40.087Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-48418 vulnerability.

Vendors Products
Edimax
  • Br-6476ac
  • Br-6476ac Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-48418.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact