Edimax manufactures a focused line of networking and wireless connectivity devices, including routers and access points, many of which serve small-business and consumer deployments with extended lifecycles. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, concentrating in flagship router models such as the BR-6478AC and the EW-7438RPN Mini through recurring weakness classes including OS command injection, buffer overflows, code injection, and CSRF that are characteristic of embedded firmware with limited input validation and privilege boundaries. The critical nature of these flaws, coupled with the internet-facing role of affected devices, creates meaningful risk for environments that depend on end-of-life or unpatched hardware. Defenders should inventory affected Edimax devices, prioritize firmware updates where available, and restrict administrative access; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Edimax over time
Signals from CVEs in this vendor scope (66 CVEs).
66 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1316CRITICAL Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device | Mar 5, 2025 | 9.8 | 91 | YES | NO |
CVE-2025-70161CRITICAL EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without prope | Jan 9, 2026 | 9.8 | 45 | NO | NO |
CVE-2023-31983CRITICAL A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/webs without any limita | May 12, 2023 | 9.8 | 42 | NO | NO |
CVE-2025-14094CRITICAL A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm/formSysCmd. This manipulation of the argument sysCmd causes | Dec 5, 2025 | 9.8 | 41 | NO | NO |
CVE-2025-14093CRITICAL A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/formTracerouteDiagnosticRun. The manipulation of the argument ho | Dec 5, 2025 | 9.8 | 41 | NO | NO |
CVE-2023-31985CRITICAL A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the formAccept function in /bin/webs without an | May 12, 2023 | 9.8 | 35 | NO | NO |
CVE-2022-45768HIGH Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker to execute arbitrary code via the formWlanMP function. | Feb 7, 2023 | 8.8 | 35 | NO | NO |
CVE-2020-37125CRITICAL Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. A | Feb 5, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-15257CRITICAL A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formRoute of the component Web-based | Dec 30, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-15256CRITICAL A vulnerability was identified in Edimax BR-6208AC 1.02/1.03. Affected is the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component Web-based Configuration | Dec 30, 2025 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (66 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Edimax.
Media articles that mention a CVE ID that affects a product developed by Edimax — matched by CVE ID, not by vendor name.