Edimax BR-6208AC Command Injection Vulnerability in Web-Based Configuration Interface

Vulnerability

A command injection vulnerability has been identified in the Edimax BR-6208AC router, specifically in the 1.02 and 1.03 firmware versions. The issue arises in the web-based configuration interface, within the formRoute function of the /gogorm/formRoute file. The vulnerability allows remote, unauthenticated attackers to inject arbitrary system commands by manipulating the strIp, strMask, or strGateway parameters. This exploitation takes advantage of inadequate input validation and sanitization, with the injected commands executed via functions that interface with the system command execution environment.

Impact

Successful exploitation of this vulnerability allows for command injection, where an attacker can execute arbitrary commands on the device. This could potentially lead to remote code execution or privilege escalation, depending on the commands injected and the context in which they are executed.

Remediation

Edimax has stated that the BR-6208AC V2 has reached its End of Life (EOL) status and is no longer supported or maintained. As such, no firmware updates or patches will be provided for this device. Users are advised to upgrade to newer models for better security.

Added: Dec 30, 2025, 6:13 PM
Updated: Dec 30, 2025, 6:13 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
9.1
remediation
0.0
relevance
1.8
threat
6.4
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.