An OS command injection vulnerability exists in the...
Critical severity
Unreviewed
Published
Jun 20, 2025
to the GitHub Advisory Database
•
Updated Sep 23, 2025
Description
Published by the National Vulnerability Database
Jun 20, 2025
Published to the GitHub Advisory Database
Jun 20, 2025
Last updated
Sep 23, 2025
An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscmd.asp form handler. The /goform/formSysCmd endpoint exposes a system command interface through the sysCmd parameter. A remote authenticated attacker can submit arbitrary shell commands directly, resulting in command execution as the root user.
References