First published: Mon Jan 27 2025(Updated: )
In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC | =1.06 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48418 is considered a high severity vulnerability due to its ability to allow arbitrary command execution on the affected router.
To fix CVE-2024-48418, update the Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC to the latest firmware version provided by Edimax.
The consequences of CVE-2024-48418 include potential unauthorized access and control over the router, allowing attackers to execute arbitrary commands.
CVE-2024-48418 affects users of the Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC running version 1.06.
A workaround for CVE-2024-48418 includes restricting access to the web interface to trusted network users until a firmware update can be applied.