CVE-2025-28146
Description
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel
In plain language
AI Worth attentionIf you run an Edimax BR-6478AC V3 router on firmware 1.0.15 (and possibly Edimax BR-6476AC), an attacker could remotely trick the router into running malicious commands—so you should act to update or mitigate quickly.
CVE-2025-28146 is a remote command injection in Edimax BR-6478AC V3 firmware 1.0.15 via the fota_url parameter in /boafrm/formLtefotaUpgradeQuectel, enabling unauthenticated attackers to execute arbitrary system commands over the network.
What to do now
- Check your router model and firmware version (look for BR-6478AC V3 and firmware 1.0.15; also verify if you use BR-6476AC).
- If you are on BR-6478AC V3 firmware 1.0.15, upgrade to the latest Edimax firmware that fixes CVE-2025-28146 (confirm the fix with Edimax release notes or support).
- If no fixed firmware is available yet, restrict access to the router from the internet (tighten firewall rules) and block/limit access to the affected web endpoint from untrusted networks.
- If you must keep the router exposed, add application-level filtering (for example, a WAF or equivalent reverse-proxy filtering) to block requests attempting to manipulate fota_url.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-28146 and every CVE in our database. Create a free account — no credit card required.
Create Free Account