CRITICAL · 9.8

CVE-2025-70161

EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An a...

Vulnerability Description

EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbitrary code execution.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
EdimaxBr-6208Ac Firmware1.03
EdimaxBr-6208Ac2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-70161?

CVE-2025-70161 is a vulnerability with a CVSS score of 9.8 (CRITICAL). EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An a...

How severe is CVE-2025-70161?

CVE-2025-70161 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2025-70161?

Check the references section above for vendor advisories and patch information. Affected products include: Edimax Br-6208Ac Firmware, Edimax Br-6208Ac.