CVE-2024-48419: Command Injection
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an attacker with access to the web interface to inject and execute arbitrary shell commands, with "root" privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48419?
CVE-2024-48419 is classified as a high severity vulnerability due to the potential for command injection by an attacker.
How do I fix CVE-2024-48419?
To fix CVE-2024-48419, update your Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC to the latest firmware version provided by Edimax.
What devices are affected by CVE-2024-48419?
CVE-2024-48419 affects the Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC running firmware version 1.06.
What vulnerabilities are associated with CVE-2024-48419?
CVE-2024-48419 is associated with command injection vulnerabilities found in specific endpoints such as /goform/tracerouteDiagnosis and /goform/pingDiagnosis.
Can CVE-2024-48419 be exploited remotely?
Yes, CVE-2024-48419 can be exploited remotely by an attacker with access to the router's web interface.