CVE-2026-9378: Edimax BR-6675nD POST Request formHwSet command injection
A security flaw has been discovered in Edimax BR-6675nD 1.12. This affects the function formHwSet of the file /goform/formHwSet of the component POST Request Handler. The manipulation of the argument regDomain/ABandregDomain/nic0Addr/nic1Addr/wlanAddr/inicAddr results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9378?
The severity of CVE-2026-9378 is medium with a score of 6.3.
How do I fix CVE-2026-9378?
To fix CVE-2026-9378, update the Edimax BR-6675nD firmware to the latest version provided by the manufacturer.
What components are affected by CVE-2026-9378?
CVE-2026-9378 affects the POST Request Handler in the formHwSet function of the Edimax BR-6675nD.
What type of vulnerability is CVE-2026-9378?
CVE-2026-9378 is classified as a command injection vulnerability.
What is the impact of exploiting CVE-2026-9378?
Exploiting CVE-2026-9378 can lead to unauthorized command execution on the Edimax BR-6675nD.