An OS command injection vulnerability exists in the...
Critical severity
Unreviewed
Published
Jun 20, 2025
to the GitHub Advisory Database
•
Updated Jun 20, 2025
Description
Published by the National Vulnerability Database
Jun 20, 2025
Published to the GitHub Advisory Database
Jun 20, 2025
Last updated
Jun 20, 2025
An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters to achieve arbitrary command execution as the root user.
References