CVE-2026-19963: Edimax EW-7478APC stainfo command injection
A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function stainfo of the file /goform/stainfo. The manipulation of the argument interface leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19963?
The severity of CVE-2026-19963 is rated as high with a score of 7.4.
How do I fix CVE-2026-19963?
To fix CVE-2026-19963, update the Edimax EW-7478APC firmware to the latest version that addresses this vulnerability.
What type of attacks can be executed due to CVE-2026-19963?
CVE-2026-19963 allows remote attackers to execute command injection attacks via the 'interface' parameter.
Who is affected by CVE-2026-19963?
Users of the Edimax EW-7478APC running firmware version 1.04 are affected by CVE-2026-19963.
When was CVE-2026-19963 published?
CVE-2026-19963 was published on August 16, 2026.