CRITICAL🇵🇱 Wersja polska

CVE-2025-34029

CVSS 9.4v4.0pub. 2025-06-20upd. 2025-11-20

An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscmd.asp form handler. The /goform/formSysCmd endpoint exposes a system command interface through the sysCmd parameter. A remote authenticated attacker can submit arbitrary shell commands directly, resulting in command execution as the root user. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-14 UTC.

🤖 AI Analysis
How it works

The vulnerability exists in the handling of the syscmd.asp form, available at the /goform/formSysCmd endpoint. The sysCmd parameter accepts user input without proper validation and sanitization, allowing arbitrary system shell commands to be passed directly. An authenticated attacker can submit a crafted HTTP request containing malicious commands that will be executed by the device's operating system with the highest privileges (root). The Shadowserver Foundation organization documented evidence of exploitation of this vulnerability on 2024-09-14 UTC.

Impact

The attacker gains full control over the device with root privileges, enabling execution of arbitrary system commands, modification of configuration, network traffic interception, and potential use of the device as a starting point for further attacks on the local network.

Mitigation & patch

Security patches available from the manufacturer should be applied according to the references. If an update is not available or cannot be deployed immediately, it is recommended to restrict access to the device's administrative panel to trusted IP addresses only and isolate the device from critical network segments.

Who is affected

Edimax EW-7438RPn Mini — firmware version 1.13 and all earlier versions.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Edimax Ew 7438rpn Mini

    HW
    Edimax
    all versions
  • Edimax Ew 7438rpn Mini Firmware

    OS
    Edimax
    ≤ 1.13
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2020-37125CRITICAL9.3PL ✓same product

RCE bez uwierzytelnienia w Edimax EW-7438RPn Mini przez endpoint /goform/mp

CVE-2025-34024CRITICAL9.4PL ✓same product

OS Command Injection w Edimax EW-7438RPn Mini — wykonanie poleceń jako root

CVE-2020-37150HIGH8.7same product

Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unset...

CVE-2020-37097HIGH8.7same product

Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuratio...

CVE-2016-10863HIGH8.8same product

Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.