Edimax AC1200 Wi-Fi 5 Dual-Band Router Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the Edimax AC1200 Wi-Fi 5 Dual-Band Router model BR-6476AC, specifically in firmware version 1.06. The vulnerability resides in the binary application '/bin/goahead' and can be exploited through the web interface pages '/goform/tracerouteDiagnosis', '/goform/pingDiagnosis', and '/goform/fromSysToolPingCmd'. This issue allows attackers to inject and execute arbitrary shell commands with root privileges. Additionally, the absence of anti-CSRF mechanisms enables potential remote exploitation using CSRF techniques.

Impact

Exploitation of this vulnerability allows for arbitrary command execution with root privileges on the affected router.

Reproduction

To reproduce this vulnerability, access the web interface of the Edimax AC1200 BR-6476AC router running firmware 1.06. Navigate to one of the vulnerable diagnosis pages: '/goform/tracerouteDiagnosis', '/goform/pingDiagnosis', or '/goform/fromSysToolPingCmd'. Inject a payload that includes the desired shell command. Once the payload is executed, the command will be executed on the router's operating system with root privileges. As a result, a new webpage can be created on the router, demonstrating successful exploitation.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.5
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.