PT-2026-73177 · Edimax · Ew-7478Apc

·

CVE-2026-19962

·

Published

2026-08-16

·

Updated

2026-08-17

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Edimax EW-7478APC version 1.04
Description A remote command injection flaw exists in the setWAN() function within the '/goform/setWAN' endpoint. This issue occurs when the pppUserName, pptpUserName, or L2TPUserName arguments are manipulated, allowing an attacker to execute arbitrary commands on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the pppUserName, pptpUserName, and L2TPUserName parameters in the '/goform/setWAN' endpoint to minimize the risk of exploitation.

Exploit

Special Elements Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19962

Affected Products

Ew-7478Apc