Edimax BR-6208AC Command Injection Vulnerability in L2TP Mode

Vulnerability

A command injection vulnerability has been identified in the Edimax BR-6208AC router, specifically in version 1.02. The issue arises in the L2TP Mode component, within the setWAN function of the /goform/setWAN file. The vulnerability can be exploited remotely by manipulating the L2TPUserName argument. This flaw has been publicly disclosed and is available for exploitation.

Impact

Exploitation of this vulnerability allows for command injection on the affected device.

Added: May 3, 2026, 7:20 AM
Updated: May 3, 2026, 7:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
9.1
remediation
0.0
relevance
7.3
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.