CVE-2025-28145: Command Injection
Published Apr 15, 2025
·Updated
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafrm/formDiskFormat.
Affected Software
3 affected components
Edimax BR-6478AC V3
All of the following
Edimax Br-6478ac V3 Firmware=1.0.15
Edimax BR-6478AC V3
Event History
Apr 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-28145?
CVE-2025-28145 has been classified as a critical severity vulnerability due to its potential for command injection.
2
How do I fix CVE-2025-28145?
To fix CVE-2025-28145, apply the latest firmware update provided by Edimax for the BR-6478AC V3 model.
3
What are the potential impacts of CVE-2025-28145?
The impacts of CVE-2025-28145 include unauthorized command execution and complete compromise of the affected router.
4
Which devices are affected by CVE-2025-28145?
CVE-2025-28145 affects the Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 with firmware version 1.0.15.
5
Is CVE-2025-28145 exploitable remotely?
Yes, CVE-2025-28145 is exploitable remotely, allowing attackers to execute commands on the vulnerable device.