CVE-2026-12809Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the component POST Request Handler. Such manipulation of the argument newpass leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-21: 3Technical Details · 2026-06-21: 306-21
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12809 A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the component POST Req… https://www.cve.org/CVERecord?id=CVE-2026-12809 ----- Traducción: CVE-2026-12809 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-12809 for a function in an Edimax device, offering minimal technical detail and no evidence of exploitation, patches, or a PoC.

    0000029
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-12809 A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the component POST Req… https://www.cve.org/CVERecord?id=CVE-2026-12809

    Post summary

    The snippet announces CVE-2026-12809 affecting Edimax BR‑6478AC V2, specifically the wiz_5in1_redirect function, but provides no evidence of exploitation, PoC, or patch information.

    00000732
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-12809 Command Injection in Edimax BR-6478AC V2 1.23 POST Request Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-12809

    Post summary

    A command injection vulnerability (CVE-2026-12809) in the Edimax BR‑6478AC V2 1.23 POST request handler is reported without any PoC, exploit code, active exploitation claim, or patch details.

    00000110
    4.1K followersView on X

Explore more