CVE-2024-48418

In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:edimax:br-6476ac_firmware:1.06:*:*:*:*:*:*:*
cpe:2.3:h:edimax:br-6476ac:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-27 17:15

Updated : 2025-05-28 17:53


NVD link : CVE-2024-48418

Mitre link : CVE-2024-48418

CVE.ORG link : CVE-2024-48418


JSON object : View

Products Affected

edimax

  • br-6476ac_firmware
  • br-6476ac
CWE
CWE-352

Cross-Site Request Forgery (CSRF)