CVE-2026-12807: Edimax BR-6478AC V2 POST Request setWAN command injection
A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Handler. The manipulation of the argument pppUserName/pptpUserName/L2TPUserName results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12807?
CVE-2026-12807 has a medium severity score of 6.3.
How do I fix CVE-2026-12807?
To fix CVE-2026-12807, update your Edimax BR-6478AC V2 device to the latest firmware provided by the manufacturer.
What type of vulnerability is CVE-2026-12807?
CVE-2026-12807 is classified as a command injection vulnerability.
Can CVE-2026-12807 be exploited remotely?
Yes, CVE-2026-12807 can be exploited remotely.
Which component is affected by CVE-2026-12807?
CVE-2026-12807 affects the setWAN function in the POST Request Handler of the Edimax BR-6478AC V2.