CVE-2024-48418

Publication date

2025-01-27 00:00:00

Family

mitre

State

PUBLISHED

Description

In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.