CVE-2025-34024

An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter. An authenticated attacker can inject shell commands using shell metacharacters to achieve arbitrary command execution as the root user.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:edimax:ew-7438rpn_mini_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:edimax:ew-7438rpn_mini:-:*:*:*:*:*:*:*

History

23 Sep 2025, 15:34

Type Values Removed Values Added
CPE cpe:2.3:h:edimax:ew-7438rpn_mini:-:*:*:*:*:*:*:*
cpe:2.3:o:edimax:ew-7438rpn_mini_firmware:*:*:*:*:*:*:*:*
References () https://vulncheck.com/advisories/edimax-ew-7438rpn-command-injections - () https://vulncheck.com/advisories/edimax-ew-7438rpn-command-injections - Exploit, Third Party Advisory
References () https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=32163 - () https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=32163 - Third Party Advisory
References () https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/global/wi-fi_range_extenders_n300/ew-7438rpn_mini/ - () https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/global/wi-fi_range_extenders_n300/ew-7438rpn_mini/ - Product
References () https://www.exploit-db.com/exploits/48377 - () https://www.exploit-db.com/exploits/48377 - Exploit, VDB Entry
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Edimax ew-7438rpn Mini
Edimax
Edimax ew-7438rpn Mini Firmware

23 Jun 2025, 20:16

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de inyección de comandos del sistema operativo en el firmware 1.13 y anteriores del Edimax EW-7438RPn a través del controlador de formularios mp.asp. El endpoint /goform/mp gestiona incorrectamente la entrada del usuario al parámetro de comando. Un atacante autenticado puede inyectar comandos de shell utilizando metacaracteres de shell para ejecutar comandos arbitrarios como usuario root.

20 Jun 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-20 19:15

Updated : 2025-09-23 15:34


NVD link : CVE-2025-34024

Mitre link : CVE-2025-34024

CVE.ORG link : CVE-2025-34024


JSON object : View

Products Affected

edimax

  • ew-7438rpn_mini
  • ew-7438rpn_mini_firmware
CWE
CWE-20

Improper Input Validation

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')