← back

CVE-2026-7683

MEDIUM · 6.3
hype MOSTLY HYPE · 28 hack

PoC public but feeds only; no KEV, vendor silent, no wild exploitation signal yet.

What: Command injection in Edimax BR-6428nC router Web Interface (/goform/setWAN, pppUserName/pptpUserName parameter) affecting firmware up to v1.16; CVSS 6.3 MEDIUM.

Why it matters: Public PoC available and vendor non-responsive to early disclosure. Not yet KEV-listed. Affects consumer routers; exploit is remotely exploitable but requires network access to Web Interface (likely internal or exposed). Medium severity limits immediate urgency.

Where it's seen: Automated feed amplification (CVE feeds, vulnerability aggregators) on publication day; no independent researcher analysis or active exploitation reports visible. Chatter is advisory rebroadcast, not operational defender triage.

RISK: MODERATE — Public PoC, unpatched router, but limited attack surface and medium CVSS.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 5/3/2026, 8:45:49 AM

Public PoCs on GitHub 1 repo

Articles & coverage 15 articles

Page 1 of 3
NVD details 2 CWE ·0 vendors · 6 refs expand

Description

A weakness has been identified in Edimax BR-6428nC up to 1.16. This affects an unknown function of the file /goform/setWAN of the component Web Interface. This manipulation of the argument pppUserName/pptpUserName causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Weaknesses

References

Top posts driving the trend