Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Edimax

First CVE: Dec 31, 2004Active for: 22 yearsTotal CVEs: 66
65.5
VTI Score
TOP TARGET

Edimax manufactures a focused line of networking and wireless connectivity devices, including routers and access points, many of which serve small-business and consumer deployments with extended lifecycles. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, concentrating in flagship router models such as the BR-6478AC and the EW-7438RPN Mini through recurring weakness classes including OS command injection, buffer overflows, code injection, and CSRF that are characteristic of embedded firmware with limited input validation and privilege boundaries. The critical nature of these flaws, coupled with the internet-facing role of affected devices, creates meaningful risk for environments that depend on end-of-life or unpatched hardware. Defenders should inventory affected Edimax devices, prioritize firmware updates where available, and restrict administrative access; live exploitation and severity counts are shown alongside this summary.

FAUCET AI Generated
66
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
1.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Edimax over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Mar 17, 2026
129 days ago

Products(46 total)

Top CVEs

Signals from CVEs in this vendor scope (66 CVEs).

66 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-1316CRITICAL
Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device
Mar 5, 20259.891YESNO
CVE-2025-70161CRITICAL
EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without prope
Jan 9, 20269.845NONO
CVE-2023-31983CRITICAL
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/webs without any limita
May 12, 20239.842NONO
CVE-2025-14094CRITICAL
A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm/formSysCmd. This manipulation of the argument sysCmd causes
Dec 5, 20259.841NONO
CVE-2025-14093CRITICAL
A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/formTracerouteDiagnosticRun. The manipulation of the argument ho
Dec 5, 20259.841NONO
CVE-2023-31985CRITICAL
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the formAccept function in /bin/webs without an
May 12, 20239.835NONO
CVE-2022-45768HIGH
Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker to execute arbitrary code via the formWlanMP function.
Feb 7, 20238.835NONO
CVE-2020-37125CRITICAL
Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. A
Feb 5, 20269.834NONO
CVE-2025-15257CRITICAL
A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formRoute of the component Web-based
Dec 30, 20259.834NONO
CVE-2025-15256CRITICAL
A vulnerability was identified in Edimax BR-6208AC 1.02/1.03. Affected is the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component Web-based Configuration
Dec 30, 20259.832NONO
View all 66 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products66 CVEs
27%
38%
35%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network52 (78.8%)
Unknown5 (7.6%)
Physical0 (0.0%)
Adjacent Network9 (13.6%)
Attack Complexity
Low57 (86.4%)
High4 (6.1%)
Unknown5 (7.6%)
User Interaction
None50 (75.8%)
Unknown5 (7.6%)
Required11 (16.7%)
Privileges Required
Low9 (13.6%)
High2 (3.0%)
None50 (75.8%)
Unknown5 (7.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (66 CVEs).

CISA KEV
1 CVE
1.5% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.5% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Edimax.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Edimax — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Edimax's Products

View all 5 CNAs →

Top CWEs