Vulnerability Description
EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbitrary code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Edimax | Br-6208Ac Firmware | 1.03 |
| Edimax | Br-6208Ac | 2.0 |
Related Weaknesses (CWE)
References
- https://tzh00203.notion.site/EDIMAX-BR-6208AC-V2_1-02-Command-Injection-VulnerabExploitThird Party Advisory
FAQ
What is CVE-2025-70161?
CVE-2025-70161 is a vulnerability with a CVSS score of 9.8 (CRITICAL). EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An a...
How severe is CVE-2025-70161?
CVE-2025-70161 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-70161?
Check the references section above for vendor advisories and patch information. Affected products include: Edimax Br-6208Ac Firmware, Edimax Br-6208Ac.