Sceawere

Vulnerability Detail

CVE-2026-19960UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Edimax EW-7478APC formWlbasic Command Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.4
Creation Date
3h ago
Vendor
Edimax
Product
EW-7478APC
Attack Type
Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such manipulation of the argument rootAPmac leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.4",
  "pubDate": "2026-08-16T23:16:24.870Z",
  "pubdate": "2026-08-16T23:16:24.870Z",
  "executiveSummary": "A critical security vulnerability has been identified in the Edimax EW-7478APC router running firmware version 1.04. The vulnerability is classified as an OS command injection flaw, stemming from the insecure handling of user-supplied input within a specific web management binary. Specifically, the weakness resides in the formWlbasic function exposed via the HTTP interface at the endpoint /goform/formWlbasic.\nSuccessful exploitation of this vulnerability allows a remote, unauthenticated attacker to execute arbitrary operating system commands with elevated privileges on the underlying device. This compromises the entire integrity, confidentiality, and availability of the affected system. The attack vector is fully network-accessible, requiring only HTTP connectivity to the router's management interface.\nPublic disclosure of a functional exploit increases the risk of exploitation by malicious actors scanning for vulnerable perimeter devices. Because the vendor was notified of the disclosure but failed to provide a response or official patch, the risk profile for deployed units remains high. Immediate defensive measures, such as restricting administrative access, are strongly recommended to mitigate exposure.",
  "technicalDetails": "The vulnerability is an OS command injection flaw located in the formWlbasic function of the /goform/formWlbasic binary on Edimax EW-7478APC version 1.04. The root cause of the vulnerability is the unsafe passing of unvalidated HTTP request parameters directly into system execution functions, such as system(), popen(), or equivalent C library wrappers, without proper sanitization or escaping.\nThe specific attack vector involves the rootAPmac argument processed by the formWlbasic endpoint. During normal operations, the application extracts the value of the rootAPmac parameter from the incoming HTTP POST or GET request to configure wireless settings. However, the lack of input filtering allows an attacker to inject shell metacharacters, such as semicolons, pipe symbols, or backticks, directly into the parameter string.\nThe attack flow proceeds as follows: First, the remote attacker crafts an HTTP request targeting the /goform/formWlbasic URI. Second, the attacker populates the rootAPmac argument with a payload containing malicious shell commands concatenated with legitimate or dummy MAC address strings. Third, the web server daemon parses the request and invokes the vulnerable formWlbasic function, passing the unsanitized string into the underlying operating system shell context.\nBecause the embedded web server and its associated administrative CGI binaries typically execute with root or administrative privileges on SOHO router platforms, the injected commands inherit these high-level privileges. Consequently, the execution of arbitrary commands results in full system compromise, enabling attackers to modify system configurations, establish persistent backdoors, pivot deeper into the internal network, or cause a denial of service.\nThe vulnerability requires network exposure to the router's web management interface, which is often accessible via the local area network (LAN) and, in misconfigured environments, via the wide area network (WAN). Exploitation does not require prior authentication or specialized user interaction, making automated exploitation via malicious scripts highly feasible."
}
CVE-2026-19960: Edimax EW-7478APC formWlbasic Command Injection (HIGH Severity, CVSS: 7.4) - Sceawere