CVE-2026-1972 describes a high-severity vulnerability in the Edimax BR-6208AC 2_1.02 router firmware, specifically within the auth_check_userpass2 function. This flaw allows remote attackers to bypass authentication by manipulating the Username/Password arguments, leading to the use of default credentials. The vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and high confidentiality impact. While public exploit code exists, there is no evidence of active exploitation, and it has received minimal community discussion or media coverage. Edimax has confirmed the affected product is end-of-life and will not receive patches.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.02CPE matchmatch criteria | cpe:2.3:o:edimax:br-6208ac_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.