Edimax Br-6478Ac V3 Firmware vulnerabilities
8 known vulnerabilities affecting edimax/br-6478ac_v3_firmware.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH1MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2025-14093P2CRITICALCVSS 9.8v1.0.152025-12-05
CVE-2025-14093 [CRITICAL] CWE-77 CVE-2025-14093: A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of t
A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/formTracerouteDiagnosticRun. The manipulation of the argument host results in os command injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure b
nvd
CVE-2025-14094P2CRITICALCVSS 9.8v1.0.152025-12-05
CVE-2025-14094 [CRITICAL] CWE-77 CVE-2025-14094: A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4
A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm/formSysCmd. This manipulation of the argument sysCmd causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did
nvd
CVE-2025-28146P2CRITICALCVSS 9.8v1.0.152025-04-04
CVE-2025-28146 [CRITICAL] CWE-94 CVE-2025-28146: Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a comman
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel
nvd
CVE-2025-14092P2HIGHCVSS 7.2v1.0.152025-12-05
CVE-2025-14092 [HIGH] CWE-77 CVE-2025-14092: A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. This issue affects the fun
A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. This issue affects the function sub_416898 of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted earl
nvd
CVE-2025-28142P3MEDIUMCVSS 6.5v1.0.152025-04-15
CVE-2025-28142 [MEDIUM] CWE-77 CVE-2025-28142: Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a comman
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /boafrm/formDiskCreateShare.
nvd
CVE-2025-28145P3MEDIUMCVSS 6.5v1.0.152025-04-15
CVE-2025-28145 [MEDIUM] CWE-77 CVE-2025-28145: Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a comman
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafrm/formDiskFormat.
nvd
CVE-2025-28143P3MEDIUMCVSS 6.5v1.0.152025-04-15
CVE-2025-28143 [MEDIUM] CWE-77 CVE-2025-28143: Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a comman
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at the /boafrm/formDiskCreateGroup.
nvd
CVE-2025-28144P3MEDIUMCVSS 6.5v1.0.152025-04-15
CVE-2025-28144 [MEDIUM] CWE-121 CVE-2025-28144: Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerability via peerPin parameter in the formWsc function.
nvd