CVE-2025-34029: Edimax EW-7438RPn Mini OS Command Injection via syscmd.asp
An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscmd.asp form handler. The /goform/formSysCmd endpoint exposes a system command interface through the sysCmd parameter. A remote authenticated attacker can submit arbitrary shell commands directly, resulting in command execution as the root user. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-14 UTC.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34029?
CVE-2025-34029 is classified as a high severity OS command injection vulnerability.
How do I fix CVE-2025-34029?
To fix CVE-2025-34029, update the firmware of the Edimax EW-7438RPn Mini to version 1.14 or later.
What type of attack can be executed using CVE-2025-34029?
A remote authenticated attacker can exploit CVE-2025-34029 to execute arbitrary system commands.
Which devices are affected by CVE-2025-34029?
CVE-2025-34029 affects the Edimax EW-7438RPn Mini firmware version 1.13 and prior.
Can CVE-2025-34029 be exploited without authentication?
No, CVE-2025-34029 requires remote authentication to exploit the vulnerability.