CVE-2026-13581: Edimax EW-7478APC POST Request formStaDrvSetup os command injection
A vulnerability was detected in Edimax EW-7478APC 1.04. This vulnerability affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. The manipulation of the argument rootAPmac results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13581?
The severity of CVE-2026-13581 is rated as medium with a score of 6.3.
How do I fix CVE-2026-13581?
To fix CVE-2026-13581, users should update their Edimax EW-7478APC firmware to the latest version provided by the vendor.
What type of vulnerability is CVE-2026-13581?
CVE-2026-13581 is classified as an OS Command Injection vulnerability.
Can CVE-2026-13581 be exploited remotely?
Yes, CVE-2026-13581 can be exploited remotely through an affected device's POST request handler.
What is affected by CVE-2026-13581?
CVE-2026-13581 affects the Edimax EW-7478APC, specifically the formStaDrvSetup function in the /goform/formStaDrvSetup file.