Metrics
Affected Vendors & Products
Wed, 27 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 May 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in Edimax EW-7438RPn 1.31. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component Content-Type Handler. Executing a manipulation of the argument ateFunc/ateGain/ateTxCount/ateChan/ateRate/ateMacID/e2pTxPower1/e2pTxPower2/e2pTxPower3/e2pTxPower4/e2pTxPower5/e2pTxPower6/e2pTxPower7/e2pTx2Power1/e2pTx2Power2/e2pTx2Power3/e2pTx2Power4/e2pTx2Power5/e2pTx2Power6/e2pTx2Power7/ateTxFreqOffset/ateMode/ateBW/ateAntenna/e2pTxFreqOffset/e2pTxPwDeltaB/e2pTxPwDeltaG/e2pTxPwDeltaMix/e2pTxPwDeltaN/readE2P can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Edimax EW-7438RPn Content-Type formWlanMP os command injection | |
| First Time appeared |
Edimax
Edimax ew-7438rpn |
|
| Weaknesses | CWE-77 CWE-78 |
|
| CPEs | cpe:2.3:a:edimax:ew-7438rpn:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Edimax
Edimax ew-7438rpn |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-05-25T04:00:15.135Z
Updated: 2026-05-27T19:36:53.432Z
Reserved: 2026-05-24T06:59:11.798Z
Link: CVE-2026-9424
Updated: 2026-05-27T19:36:48.886Z
Status : Deferred
Published: 2026-05-25T05:16:16.737
Modified: 2026-05-26T19:37:00.120
Link: CVE-2026-9424
No data.
ReportizFlow