CVE-2025-14093: Edimax BR-6478AC V3 formTracerouteDiagnosticRun sub_416990 os command injection
A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub416990 of the file /boafrm/formTracerouteDiagnosticRun. The manipulation of the argument host results in os command injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14093?
CVE-2025-14093 is considered a high severity vulnerability due to the potential for remote command injection.
How do I fix CVE-2025-14093?
To mitigate CVE-2025-14093, it is recommended to update the Edimax BR-6478AC V3 to the latest firmware version provided by Edimax.
What type of attack is associated with CVE-2025-14093?
CVE-2025-14093 is associated with remote OS command injection attacks.
Which device is affected by CVE-2025-14093?
CVE-2025-14093 specifically affects the Edimax BR-6478AC V3 router.
Can CVE-2025-14093 be exploited remotely?
Yes, CVE-2025-14093 can be exploited remotely by an attacker.