SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2025-34024

An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler.

CRITICAL 9.4EPSS 3.88%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters to achieve arbitrary command execution as the root user. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-14 UTC.

CVSS 4.0
9.4 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
3.88% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
edimax/ew-7438rpn mini firmware
Source
disclosure@vulncheck.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.