CVE-2025-34024: Edimax EW-7438RPn Mini OS Command Injection via mp.asp
An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters to achieve arbitrary command execution as the root user. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-14 UTC.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34024?
CVE-2025-34024 is classified as a high-severity OS command injection vulnerability.
How do I fix CVE-2025-34024?
To mitigate CVE-2025-34024, users should upgrade the firmware of the Edimax EW-7438RPn to version 1.14 or later.
What impact does CVE-2025-34024 have on affected systems?
CVE-2025-34024 allows an authenticated attacker to execute arbitrary shell commands on the affected device.
Who is affected by CVE-2025-34024?
CVE-2025-34024 affects users of Edimax EW-7438RPn firmware version 1.13 and earlier.
What is the attack vector for CVE-2025-34024?
The attack vector for CVE-2025-34024 is through the mp.asp form handler at the /goform/mp endpoint.