CVE-2026-9362: Edimax EW-7438RPn Setting formConnectionSetting command injection
A security vulnerability has been detected in Edimax EW-7438RPn 1.12. This vulnerability affects the function formConnectionSetting of the file /goform/formConnectionSetting of the component Setting Handler. Such manipulation of the argument maxConn/timeOut leads to command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable remote/remote-administration access to the device's web management interface to prevent remote exploitation of formConnectionSetting.
Edimax EW-7438RPn (web administration interface) remote_management = disabled - Compensating control
Use network firewall/ACLs to restrict access to the device's management interface to only trusted IP addresses or management networks; block access from the Internet.
- Compensating control
Deploy a WAF or reverse-proxy rule to block or filter requests to /goform/formConnectionSetting (the vulnerable endpoint) to prevent exploitation of the formConnectionSetting function.
- Operational
Remove the device from untrusted networks or take it offline until a vendor patch or other fix is available.
- Operational
If the device was exposed, perform integrity and compromise checks, restore from known-good firmware/backup if compromise is detected, and rotate any credentials that may have been used to access the device.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9362?
The severity of CVE-2026-9362 is rated medium with a CVSS score of 6.3.
How do I fix CVE-2026-9362?
To fix CVE-2026-9362, the affected Edimax EW-7438RPn device should be updated to the latest firmware version provided by the manufacturer.
What can be exploited in CVE-2026-9362?
CVE-2026-9362 can be exploited through command injection via manipulation of the max_Conn/timeOut arguments in the formConnectionSetting function.
What devices are affected by CVE-2026-9362?
CVE-2026-9362 affects the Edimax EW-7438RPn wireless range extender.
What is the potential impact of CVE-2026-9362?
The potential impact of CVE-2026-9362 includes unauthorized command execution on the affected device, which could lead to further system compromises.