Edimax AC1200 Router Command Injection Vulnerability via DDNS Interface
Vulnerability
A command injection vulnerability has been identified in the Edimax AC1200 Wi-Fi 5 Dual-Band Router model BR-6476AC, specifically in firmware version 1.06. The vulnerability arises in the request '/goform/fromSetDDNS', which fails to properly sanitize special characters in user-provided parameters. This flaw allows an attacker with access to the web interface to inject and execute arbitrary shell commands with root privileges. Additionally, the absence of anti-CSRF measures enables remote exploitation of this vulnerability through CSRF techniques.
Impact
Exploitation of this vulnerability allows for arbitrary command execution on the router's operating system with root privileges.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
