peter bassill · operator
$ cve CVE-2025-70161 JSON

CVE-2025-70161

9.8
CRITICAL · CVSS 3.1 · EPSS 27.1% (pctl 98)

Patch early

EPSS 27.1% — above the 10% action threshold.

Description

EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbitrary code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS27.06% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2026-01-09
Last modified2026-06-17

Affected (2)

VendorProduct
edimaxbr-6208ac
edimaxbr-6208ac firmware

References

→ the Explorer  ·  watch your stack  ·  NVD