CVE-2025-70161: Command Injection
EDIMAX BR-6208AC V21.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70161?
CVE-2025-70161 has a medium severity rating due to the potential for command injection vulnerabilities allowing remote code execution.
How do I fix CVE-2025-70161?
To fix CVE-2025-70161, update the firmware of the Edimax BR-6208AC V2 to the latest version that addresses this vulnerability.
What is the impact of CVE-2025-70161 on my device?
The impact of CVE-2025-70161 includes unauthorized remote command execution, which can compromise device integrity and lead to data breaches.
Which products are affected by CVE-2025-70161?
CVE-2025-70161 specifically affects the Edimax BR-6208AC V2 router model.
Is there a workaround for CVE-2025-70161?
A potential workaround for CVE-2025-70161 is to limit access to the device's management interface to trusted IP addresses until a firmware update can be applied.