Edimax BR-6288ACL Cross-Site Scripting Vulnerability in WISP Manual Configuration Function

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the Edimax BR-6288ACL router, affecting versions through 1.12. The issue arises in the 'wiz_WISP24gmanual' function of the 'wiz_WISP24gmanual.asp' file, where the 'manualssid' argument is not properly sanitized before being output. This flaw allows for the injection of malicious JavaScript, which is then stored in the router's configuration. When the configuration is accessed again, the injected script executes, resulting in stored cross-site scripting. The vulnerability can be exploited remotely and requires user interaction.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user accessing the router's configuration.

Reproduction

To reproduce this vulnerability, access the 'wiz_WISP24gmanual.asp' page on an affected Edimax BR-6288ACL router. Inject a script into the 'manualssid' field, which will be saved to the router's configuration. When the configuration is revisited, the injected script will execute, demonstrating the cross-site scripting vulnerability.

Added: Feb 6, 2026, 1:17 AM
Updated: Feb 6, 2026, 1:17 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
1.7
exploitability
5.5
remediation
0.0
relevance
2.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.