CVE-2025-22912: Command Injection
Published Jan 16, 2025
·Updated
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
Affected Software
3 affected components
Re11S Re11S
All of the following
Edimax Re11s Firmware=1.11
Edimax Re11s
Event History
Jan 16, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22912?
CVE-2025-22912 is classified as a high severity vulnerability due to its command injection capability.
2
How do I fix CVE-2025-22912?
To fix CVE-2025-22912, update the RE11S software to the latest version that resolves this vulnerability.
3
What components are affected by CVE-2025-22912?
CVE-2025-22912 affects the component /goform/formAccept in RE11S v1.11.
4
What can an attacker do with CVE-2025-22912?
An attacker can exploit CVE-2025-22912 to execute arbitrary commands on the affected system.
5
Is there a workaround for CVE-2025-22912 if I can't update immediately?
As a workaround for CVE-2025-22912, restrict access to the vulnerable component to trusted users only.