What is CVE-2026-19960?
A command injection vulnerability has been found in the `formWlbasic` function of Edimax EW-7478APC version 1.04. Remote attackers can manipulate the `rootAPmac` argument to execute arbitrary commands. It is recommended to restrict network exposure and apply any available security updates from the vendor.
Azərbaycanca: Edimax EW-7478APC cihazının 1.04 versiyasında `formWlbasic` funksiyasında komanda inyeksiyası (command injection) zəifliyi aşkarlanıb. Bu, uzaqdan hücumçuya `rootAPmac` arqumenti vasitəsilə əmrləri icra etməyə imkan verir. Cihazı internetə açıq saxlamamaq və istehsalçının təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: Edimax
FAQ2
What vulnerability has been found in the Edimax EW-7478APC device and what is its CVE code?
A command injection vulnerability has been found in the `formWlbasic` function of the device version 1.04. This vulnerability is tracked as CVE-2026-19960.
How can an attacker exploit the CVE-2026-19960 vulnerability?
A remote attacker can manipulate the `rootAPmac` argument to inject and execute arbitrary commands.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.