CVE-2026-9440: Edimax BR-6478AC POST Request formAccept command injection
A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of the file /goform/formAccept of the component POST Request Handler. Such manipulation of the argument submit-url leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-9440 affects Edimax BR-6478AC firmware 1.23. An authenticated remote attacker may be able to inject system commands through a router POST request parameter. This is most urgent where these routers are still deployed and management access is reachable beyond trusted administrators.
Executive priority
Treat as a targeted network-edge risk. It is not confirmed as actively exploited, but public exploit availability and lack of vendor response justify prompt inventory, access restriction, and remediation planning.
Technical view
The vulnerability is command injection in the formAccept function for /goform/formAccept. Manipulation of the submit-url argument in the POST request handler can lead to command execution. Sources rate it CVSS v2 6.5 with network access, low complexity, and single authentication required.
Likely exposure
Exposure is likely limited to Edimax BR-6478AC devices running firmware 1.23, especially where the management interface is reachable to untrusted networks or weakly controlled authenticated users.
Exploitation context
A public exploit is referenced, but the provided sources do not show CISA KEV listing or confirmed active exploitation. The vendor reportedly did not respond, and no vendor fix is named in the bundle.
Researcher notes
Key unknowns are patch availability, authentication context, and real-world exploitation. Validate only in authorized environments. Focus on exposure mapping, management-plane access controls, and detection for suspicious formAccept activity rather than reproducing exploitation.
Mitigation direction
Inventory Edimax BR-6478AC devices and confirm firmware version 1.23 exposure.
Restrict router management access to trusted administrative networks only.
Review Edimax guidance for firmware updates or replacement advice.
Disable remote administration where it is not required.
Consider replacing affected devices if no maintained firmware is available.
Validation and detection
Confirm device model and firmware version from administrative records or device UI.
Check whether /goform/formAccept is reachable from untrusted networks.
Review access logs for unusual POST requests to /goform/formAccept.
Verify only authorized administrators can authenticate to management interfaces.
Track vendor and CVE sources for updated remediation guidance.
Based on public source material and reviewed before publication.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-74: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Command injection weaknesses can lead defenders to review execution techniques and command interpreter telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve
time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present,
the table keeps the source vectors side by side instead of collapsing them into the highest score.