CVE-2025-28143

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 15, 2025
Updated: May 1, 2025
CWE ID 77

Summary

CVE-2025-28143 is a command injection vulnerability affecting the Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15. An attacker can exploit this vulnerability by manipulating the groupname parameter in the /boafrm/formDiskCreateGroup endpoint. Successful exploitation could allow the attacker to execute arbitrary commands on the affected device with root privileges, potentially leading to unauthorized access, data theft, or system compromise. Users are advised to update their routers to the latest firmware version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share