CVE-2025-34024 Information
Jun 21, 2025
cve
Description
An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters to achieve arbitrary command execution as the root user.
Reference
https://vulncheck.com/advisories/edimax-ew-7438rpn-command-injections https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=32163 https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/global/wi-fi_range_extenders_n300/ew-7438rpn_mini/ https://www.exploit-db.com/exploits/48377
Related CNNVD
CNNVD-202506-2804 (Published: 2025-06-20)
Share on: