CVE-2025-28146: Command Injection
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fotaurl in /boafrm/formLtefotaUpgradeQuectel
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28146?
CVE-2025-28146 is rated as a high severity command injection vulnerability in the Edimax AC1200 Wave 2 Dual-Band Gigabit Router.
How do I fix CVE-2025-28146?
To mitigate CVE-2025-28146, update the Edimax AC1200 router to the latest firmware version that addresses this vulnerability.
What type of vulnerability is CVE-2025-28146?
CVE-2025-28146 is a command injection vulnerability that allows attackers to execute arbitrary commands on the affected router.
What component is affected by CVE-2025-28146?
CVE-2025-28146 affects the fota_url parameter in the /boafrm/formLtefotaUpgradeQuectel endpoint of the router.
Who is affected by CVE-2025-28146?
Users of the Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 running version 1.0.15 are affected by CVE-2025-28146.