CVE-2026-9441: Edimax BR-6478AC POST Request formiNICbasic command injection
A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. Performing a manipulation of the argument rootAPmac results in command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-9441 is a command injection flaw in Edimax BR-6478AC firmware 1.23. An authenticated remote attacker may be able to make the router run unintended system commands through a POST handler. Public proof-of-concept material is reported, but the provided sources do not show confirmed active exploitation or an available vendor fix.
Executive priority
Treat as a moderate operational priority. The flaw affects a network edge device and has public proof-of-concept material, but the provided evidence indicates authentication is required and does not confirm active exploitation.
Technical view
The flaw affects /goform/formiNICbasic in the POST request handler. Manipulation of the rootAPmac argument can result in command injection, mapped to CWE-74 and CWE-77. CVSS v2 is 6.5 with network access, low complexity, single authentication required, and partial confidentiality, integrity, and availability impact.
Likely exposure
Exposure appears limited to Edimax BR-6478AC firmware 1.23, with submission text referencing BR6478ACV2_v1.23. Risk is highest where the management interface is reachable by untrusted networks or broadly shared administrator accounts.
Exploitation context
The source bundle says an exploit has been publicly released and may be used for attacks. It does not include KEV status or other cited evidence of active exploitation. The CVSS vector indicates authentication is required.
Researcher notes
Evidence is sparse and vendor response is reportedly absent. Validate exact hardware revision carefully because the affected list names BR-6478AC 1.23 while the submission reference names BR6478ACV2_v1.23. Avoid assuming broader Edimax firmware exposure without confirmation.
Mitigation direction
Inventory Edimax BR-6478AC or BR6478ACV2 devices and identify firmware 1.23.
Check Edimax and VulDB guidance for a fixed firmware or official mitigation.
Restrict router administration to trusted management networks or VPN access.
Disable any unnecessary remote administration exposure where operationally possible.
Plan replacement or isolation if no supported fixed firmware is available.
Validation and detection
Confirm model and firmware version through asset records or the device administration interface.
Verify management interfaces are not exposed to the public internet.
Review administrative access paths for broad or shared authenticated access.
Inspect device or gateway logs for requests to /goform/formiNICbasic.
Look for unusual rootAPmac parameter activity without reproducing exploit behavior.
Based on public source material and reviewed before publication.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-74: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Command injection weaknesses can lead defenders to review execution techniques and command interpreter telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve
time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present,
the table keeps the source vectors side by side instead of collapsing them into the highest score.