An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters to achieve arbitrary command execution as the root user. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-14 UTC.
The vulnerability affects the form handler mp.asp, accessible through the /goform/mp endpoint. The 'command' parameter passed by the user is not properly validated or filtered, allowing injection of arbitrary shell commands using shell metacharacters (e.g., semicolon, pipe). An authenticated attacker can execute arbitrary code as the root user. Evidence of active exploitation of this vulnerability was recorded by Shadowserver Foundation on September 14, 2024.
An attacker gains full control of the device with root privileges, enabling configuration reading and modification, installation of malicious software, network traffic interception, and use of the device as an entry point to the internal network.
Apply patches available from the manufacturer according to references. It is recommended to check the availability of firmware updates on the Edimax manufacturer's website. As a temporary measure, restrict access to the device management interface only to trusted hosts and consider isolating the device from the rest of the network infrastructure.
Edimax EW-7438RPn Mini with firmware version 1.13 and all earlier versions.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XEdimax Ew 7438rpn Mini
HWEdimaxall versionsEdimax Ew 7438rpn Mini Firmware
OSEdimax≤ 1.13
Related vulnerabilities
RCE bez uwierzytelnienia w Edimax EW-7438RPn Mini przez endpoint /goform/mp
Command injection w Edimax EW-7438RPn Mini — wykonanie poleceń jako root
Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unset...
Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuratio...
Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.