CVE-2026-19960: Edimax EW-7478APC formWlbasic command injection
A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such manipulation of the argument rootAPmac leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19960?
The severity of CVE-2026-19960 is rated high with a score of 7.4.
How do I fix CVE-2026-19960?
To mitigate CVE-2026-19960, it is recommended to update the Edimax EW-7478APC firmware to the latest version provided by the manufacturer.
What type of attack is associated with CVE-2026-19960?
CVE-2026-19960 is associated with remote command injection attacks that exploit the formWlbasic function.
Who is affected by CVE-2026-19960?
Users of Edimax EW-7478APC version 1.04 are affected by CVE-2026-19960.
What does CVE-2026-19960 allow an attacker to do?
CVE-2026-19960 allows an attacker to execute arbitrary commands on the device remotely due to the command injection vulnerability.