Edimax · Ew-7478Apc · CVE-2026-19962
**Name of the Vulnerable Software and Affected Versions**
Edimax EW-7478APC version 1.04
**Description**
A remote command injection flaw exists in the `setWAN()` function within the '/goform/setWAN' endpoint. This issue occurs when the `pppUserName`, `pptpUserName`, or `L2TPUserName` arguments are manipulated, allowing an attacker to execute arbitrary commands on the system.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the `pppUserName`, `pptpUserName`, and `L2TPUserName` parameters in the '/goform/setWAN' endpoint to minimize the risk of exploitation.