RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.
References
| Link | Resource |
|---|---|
| http://re11s.com | Broken Link Not Applicable |
| https://github.com/xyqer1/RE11S_1.11-setWAN-CommandInjection | Exploit Third Party Advisory |
| https://www.edimax.com/edimax/global/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-01-16 03:15
Updated : 2025-04-09 18:44
NVD link : CVE-2025-22906
Mitre link : CVE-2025-22906
CVE.ORG link : CVE-2025-22906
JSON object : View
Products Affected
edimax
- re11s_firmware
- re11s
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
