A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipulation of the argument pppUserName/pptpUserName/L2TPUserName can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Sun, 16 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipulation of the argument pppUserName/pptpUserName/L2TPUserName can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Edimax EW-7478APC setWAN command injection | |
| First Time appeared |
Edimax
Edimax ew-7478apc |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:a:edimax:ew-7478apc:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Edimax
Edimax ew-7478apc |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-16T23:15:11.641Z
Reserved: 2026-08-16T07:07:49.713Z
Link: CVE-2026-19962
No data.
Status : Received
Published: 2026-08-17T00:16:26.490
Modified: 2026-08-17T00:16:26.490
Link: CVE-2026-19962
No data.
OpenCVE Enrichment
Updated: 2026-08-17T00:30:02Z