A security flaw has been discovered in Edimax BR-6208AC 1.02. The impacted element is the function setWAN of the file /goform/setWAN of the component L2TP Mode. The manipulation of the argument L2TPUserName results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Sun, 03 May 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Edimax br-6208ac
|
|
| Vendors & Products |
Edimax br-6208ac
|
Sun, 03 May 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in Edimax BR-6208AC 1.02. The impacted element is the function setWAN of the file /goform/setWAN of the component L2TP Mode. The manipulation of the argument L2TPUserName results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Edimax BR-6208AC L2TP Mode setWAN command injection | |
| First Time appeared |
Edimax
Edimax br-6208ac Firmware |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:o:edimax:br-6208ac_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Edimax
Edimax br-6208ac Firmware |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-03T06:15:09.912Z
Reserved: 2026-05-02T11:05:13.164Z
Link: CVE-2026-7682
No data.
Status : Received
Published: 2026-05-03T07:16:24.807
Modified: 2026-05-03T07:16:24.807
Link: CVE-2026-7682
No data.