What is CVE-2026-19962?
A command injection vulnerability has been discovered in the `setWAN` function of the `/goform/setWAN` file on Edimax EW-7478APC version 1.04, exploitable via the `pppUserName`, `pptpUserName`, or `L2TPUserName` parameters. This allows a remote attacker to execute arbitrary commands on the device. It is recommended to update to the latest firmware immediately or request a patch from the vendor.
Azərbaycanca: Edimax EW-7478APC 1.04 cihazında `/goform/setWAN` faylındakı `setWAN` funksiyasında `pppUserName`, `pptpUserName` və ya `L2TPUserName` parametrləri vasitəsilə uzaqdan command injection zəifliyi aşkar edilib. Bu, təcavüzkara cihazda ixtiyari əmrlər icra etməyə imkan verir. Cihazı mümkün qədər tez bir zamanda ən son proqram təminatına yeniləmək və ya istehsalçıdan yamaq tələb etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: Edimax
FAQ1
Which parameters does an attacker target to exploit the CVE-2026-19962 vulnerability on the Edimax EW-7478APC device?
An attacker can perform command injection via any of the `pppUserName`, `pptpUserName`, or `L2TPUserName` parameters in the `setWAN` function of the `/goform/setWAN` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.