CVE-2026-12807Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Handler. The manipulation of the argument pppUserName/pptpUserName/L2TPUserName results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-21: 3Technical Details · 2026-06-21: 306-21
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12807 A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Handler. The manipula… https://www.cve.org/CVERecord?id=CVE-2026-12807 ----- Traducción: CVE-2026-12807 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑12807 for Edimax BR‑6478AC V2 1.23, providing limited technical details about the affected function and file but no exploit code or patch information.

    0000027
    88 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-12807 A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Handler. The manipula… https://www.cve.org/CVERecord?id=CVE-2026-12807

    Post summary

    The update notes CVE‑2026‑12807 affecting an Edimax router’s setWAN function, with minimal technical detail but no mention of exploits, PoC, or patch.

    00000756
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-12807 Command Injection in Edimax BR-6478AC V2 1.23 POST Request Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-12807

    Post summary

    Edimax BR‑6478AC V2 1.23 is vulnerable to command injection via its POST request handler, as disclosed in CVE‑2026‑12807.

    0000084
    4.1K followersView on X

Explore more