CVE-2025-34024
20.06.2025, 19:15
An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters to achieve arbitrary command execution as the root user.Enginsight
| Vendor | Product | Version |
|---|---|---|
| edimax | ew-7438rpn_mini_firmware | 𝑥 ≤ 1.13 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References