CVE-2026-82703: Command Injection
A security flaw has been discovered in Edimax BR-6214K 1.40. This vulnerability affects the function system of the file www/ping.asp of the component aspsetPing Endpoint. Performing a manipulation of the argument pingstr results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be initiated remotely, but the supplied CVSS vector indicates high privileges are required. No user interaction is required.
Is public exploit information available?
Yes. The exploit has been publicly released and may be used in attacks.
Which endpoint and input should defenders review?
The affected component is the asp_setPing endpoint in www/ping.asp. The vulnerable input is the pingstr argument, whose manipulation can lead to operating-system command injection.
Is a vendor fix or response available?
The available information states that the vendor was contacted early but did not respond. It does not identify a fix or mitigation.