CVE-2025-34024
An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters to achieve arbitrary command execution as the root user. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-14 UTC.
- CVSS 4.0
- 9.4 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 3.88% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- edimax/ew-7438rpn mini firmware
- Source
- disclosure@vulncheck.com
References
- https://vulncheck.com/advisories/edimax-ew-7438rpn-command-injectionsExploit, Third Party Advisory
- https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=32163Third Party Advisory
- https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/global/wi-fi_range_extenders_n300/ew-7438rpn_mini/Product
- https://www.exploit-db.com/exploits/48377Exploit, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.