Loading
In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.
Use CWE-352, Edimax vendor hub and Br-6476ac Firmware product page to widen CVE-2024-48418 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-48420, CVE-2024-48419 and CVE-2024-48416 for nearby disclosures in the same product family.