CVE-2024-48419Disclosure(edimax / br-6476ac)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch edimax br-6476ac systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an attacker with access to the web interface to inject and execute arbitrary shell commands, with "root" privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • br-6476ac
  • br-6476ac_firmware

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
br-6476acbr-6476ac_firmware

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-08: 1Patch / Workaround · 2026-05-08: 1Technical Details · 2026-05-08: 105-08
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • yousukezan@yousukezan
    Disclosure

    Pythonライブラリjellyfin-apiclient-pythonに、任意のコード実行が可能な重大な脆弱性(CVE-2024-48419)が報告された。攻撃者は細工したファイル名を通じて、影響を受けるシステム上で任意のコマンドを実行できる恐れがある。 これは、get_download_headers関数でfilenameパラメータが適切にサニタイズされないことに起因する。CVSSスコア9.8のCRITICALと評価されており、バージョン0.1.0以前が影響を受ける。ユーザーは、この脆弱性を解決するため、バージョン0.1.1以降への速やかなアップグレードが推奨される。 https://github.com/advisories/GHSA-vp62-r36r-9xqp

    Post summary

    A critical remote code execution vulnerability (CVE-2024-48419) in the jellyfin-apiclient-python library has been disclosed, with detailed technical data and a recommended patch via version upgrade.

    08034155.0K
    14.4K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWedimaxbr-6476ac---
OSedimaxbr-6476ac_firmware1.06--

Explore more