CRITICAL🇵🇱 Wersja polska

CVE-2025-34024

CVSS 9.4v4.0pub. 2025-06-20upd. 2025-11-20

An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters to achieve arbitrary command execution as the root user. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-14 UTC.

🤖 AI Analysis
How it works

The vulnerability affects the form handler mp.asp, accessible through the /goform/mp endpoint. The 'command' parameter passed by the user is not properly validated or filtered, allowing injection of arbitrary shell commands using shell metacharacters (e.g., semicolon, pipe). An authenticated attacker can execute arbitrary code as the root user. Evidence of active exploitation of this vulnerability was recorded by Shadowserver Foundation on September 14, 2024.

Impact

An attacker gains full control of the device with root privileges, enabling configuration reading and modification, installation of malicious software, network traffic interception, and use of the device as an entry point to the internal network.

Mitigation & patch

Apply patches available from the manufacturer according to references. It is recommended to check the availability of firmware updates on the Edimax manufacturer's website. As a temporary measure, restrict access to the device management interface only to trusted hosts and consider isolating the device from the rest of the network infrastructure.

Who is affected

Edimax EW-7438RPn Mini with firmware version 1.13 and all earlier versions.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Edimax Ew 7438rpn Mini

    HW
    Edimax
    all versions
  • Edimax Ew 7438rpn Mini Firmware

    OS
    Edimax
    ≤ 1.13
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2020-37125CRITICAL9.3PL ✓same product

RCE bez uwierzytelnienia w Edimax EW-7438RPn Mini przez endpoint /goform/mp

CVE-2025-34029CRITICAL9.4PL ✓same product

Command injection w Edimax EW-7438RPn Mini — wykonanie poleceń jako root

CVE-2020-37150HIGH8.7same product

Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unset...

CVE-2020-37097HIGH8.7same product

Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuratio...

CVE-2016-10863HIGH8.8same product

Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.