Aller au contenu

Fiche vulnérabilité

CVE-2025-34024 : faille élevée edimax ew-7438rpn mini firmware (CVSS 8.8)

Description

An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters to achieve arbitrary command execution as the root user. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-14 UTC.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
20 juin 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • edimax ew-7438rpn mini firmware

Références

Rechercher une autre vulnérabilité dans la base CVE