CVE-2025-15256 - Edimax BR-6208AC Web-based Configuration formStaDrvSetup command injection

CVE-2025-15256 - Edimax BR-6208AC Web-based Configuration formStaDrvSetup command injection

CVE ID : CVE-2025-15256 Published : Dec. 30, 2025, 5:15 p.m. | 1 hour, 21 minutes ago Description : A vulnerability was identified in Edimax BR-6208AC 1.02/1.03. Affected is the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component Web-based Configuration Interface. The manipulation of the argument rootAPmac leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. Edimax confirms this issue:

CVE Details

Published
Dec. 30, 2025
Impact: command injection

Source: Telegram CVE Monitor