CVE-2025-56706

8.0

Edimax · BR-6473AX

A remote code execution vulnerability in the Edimax BR-6473AX router allows authenticated attackers to execute arbitrary code via the openwrt_getConfig function.

Executive summary

An authenticated remote code execution vulnerability in the Edimax BR-6473AX router poses a severe risk to network integrity and device control.

Vulnerability

This vulnerability is a remote code execution flaw triggered by the Object parameter within the openwrt_getConfig function. Successful exploitation requires an attacker to have low-level privileges to interact with the vulnerable function.

Business impact

The ability to execute arbitrary code on network infrastructure can lead to total system compromise, allowing attackers to intercept traffic, pivot into internal networks, or deploy persistent malware. With a CVSS score of 8.0, this high-severity flaw represents a significant risk to organizational security and data confidentiality.

Remediation

Immediate Action: Contact the vendor immediately to obtain the necessary firmware update to address this vulnerability, as no official patch version is currently documented.

Proactive Monitoring: Monitor network traffic for suspicious requests directed at administrative interfaces and review device logs for unexpected execution of system commands.

Compensating Controls: Restrict access to the device management interface to trusted administrative IP addresses only, and implement strict network segmentation to limit the potential blast radius.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the technical write-up referenced in the CVE record.

Analyst recommendation

Given the potential for remote code execution and the confirmed existence of a public proof-of-concept, this vulnerability must be treated with high priority. Administrators should audit their device configurations to restrict access to the management interface while awaiting specific firmware remediation from Edimax.

More Edimax CVEs

Sources