Edimax BR-6208AC Path Traversal Vulnerability in FTP Daemon Service

Vulnerability

A path traversal vulnerability has been identified in the Edimax BR-6208AC router running firmware version 1.02. The issue resides in the FTP daemon service, specifically within the handle_retr function, which improperly validates user-supplied file paths. This flaw allows authenticated attackers to read arbitrary files from the device's filesystem, potentially exposing sensitive information such as configuration files, passwords, and system details. The vulnerability can be exploited remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability allows for unauthorized reading of files from the device's filesystem, which could include sensitive information such as configuration files and passwords.

Remediation

Users are advised to disable the FTP service on the Edimax BR-6208AC router to mitigate the risks associated with this vulnerability. For those seeking to upgrade, newer, supported models are recommended.

Added: Dec 19, 2025, 2:23 AM
Updated: Dec 19, 2025, 2:23 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
6.2
remediation
7.9
relevance
1.5
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.