CVE-2026-9379: Edimax BR-6675nD POST Request formWpsStart command injection
A weakness has been identified in Edimax BR-6675nD 1.12. This impacts the function formWpsStart of the file /goform/formWpsStart of the component POST Request Handler. This manipulation of the argument pinCode causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-9379 affects Edimax BR-6675nD firmware 1.12. A remote authenticated attacker could abuse a WPS-related POST handler to run injected commands. Public proof-of-concept material is reported, but the bundle does not show active exploitation or a vendor fix.
Executive priority
Treat this as a moderate, targeted network-edge risk. Prioritize exposed or unmanaged routers first, because public exploit material lowers the barrier once an attacker has credentials or access.
Technical view
The flaw is command injection in /goform/formWpsStart, specifically the formWpsStart POST request handler processing the pinCode argument. CVSS v2 is 6.5 with network access, low complexity, and authentication required. VulDB maps it to CWE-74 and CWE-77 and notes public exploit availability.
Likely exposure
Exposure is limited to Edimax BR-6675nD devices running version 1.12, especially where administrative or WPS-related router interfaces are reachable by untrusted users.
Exploitation context
The source bundle says a public exploit exists, but KEV is false and no cited source states active exploitation. Authentication is required according to the CVSS vector and CTI permission signal.
Researcher notes
Evidence supports command injection in a specific POST handler and argument, with public PoC availability. The bundle does not include vendor confirmation, active exploitation evidence, or an official fix. Avoid assuming broader Edimax impact beyond BR-6675nD 1.12.
Mitigation direction
Check Edimax for updated firmware or advisory; no patch is named in the provided sources.
Restrict router administration interfaces to trusted networks or VPN-only access.
Remove public WAN access to management endpoints wherever present.
Replace or retire affected devices if no vendor-supported fix exists.
Review router accounts and remove unnecessary administrative access.
Validation and detection
Inventory Edimax BR-6675nD devices and confirm firmware version 1.12.
Verify management and WPS-related endpoints are not exposed to the internet.
Review device logs for unexpected POST activity to /goform/formWpsStart.
Confirm only trusted administrators can authenticate to affected routers.
Track CVE and VulDB records for vendor response or remediation updates.
Based on public source material and reviewed before publication.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-74: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Command injection weaknesses can lead defenders to review execution techniques and command interpreter telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve
time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present,
the table keeps the source vectors side by side instead of collapsing them into the highest score.