Edimax RE11S Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the Edimax RE11S router, specifically in version 1.11. The issue arises in the '/goform/mp' endpoint, where user-supplied command parameters are not properly sanitized, allowing for arbitrary command execution on the system.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected router.

Reproduction

The vulnerability can be reproduced by sending a POST request to the '/goform/mp' endpoint with a 'command' parameter containing the desired system commands. This can be done using a Python script that utilizes the 'requests' library to automate the process.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.