CVE-2025-15257
CVE-2025-15257 is a high-severity vulnerability in Edimax Br-6208ac Firmware with a CVSS 3.x base score of 7.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-77.
Key facts
- Severity: High (CVSS 3.x base score 7.3)
- CVSS v2: 7.5
- CVSS v4: 5.5
- EPSS exploit prediction: 5% (92nd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-205833
- Weakness: CWE-77
- Affected product: Edimax Br-6208ac Firmware
- Published:
- Last modified:
Description
A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formRoute of the component Web-based Configuration Interface. The manipulation of the argument strIp/strMask/strGateway results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Edimax confirms this issue: "The product mentioned, EDIMAX BR-6208AC V2, has reached its End of Life (EOL) status. It is no longer supported or maintained by Edimax, and it is no longer available for purchase in the market. Consequently, there will be no further firmware updates or patches for this device. We recommend users upgrade to newer models for better security." This vulnerability only affects products that are no longer supported by the maintainer.
Frequently asked questions
- What is CVE-2025-15257?
- A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formRoute of the component Web-based Configuration Interface. The manipulation of the argument strIp/strMask/strGateway results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Edimax confirms this issue: "The product mentioned, EDIMAX BR-6208AC V2, has reached its End of Life (EOL) status. It is no longer supported or maintained by Edimax, and it is no longer available for purchase in the market. Consequently, there will be no further firmware updates or patches for this device. We recommend users upgrade to newer models for better security." This vulnerability only affects products that are no longer supported by the maintainer.
- How severe is CVE-2025-15257?
- CVE-2025-15257 has a CVSS 3.x base score of 7.3, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2025-15257 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 5% (92nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-15257?
- CVE-2025-15257 primarily affects Edimax Br-6208ac Firmware. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2025-15257?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2025-15257 have an EU (EUVD) identifier?
- Yes. CVE-2025-15257 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-205833.
- When was CVE-2025-15257 published?
- CVE-2025-15257 was published on 2025-12-30 and last updated on 2026-06-17.
References
- https://tzh00203.notion.site/EDIMAX-BR-6208AC-V2_1-02-Command-Injection-Vulnerability-in-Web-formRoute-handler-2d3b5c52018a805983d3cf0780b28407?source=copy_link
- https://vuldb.com/?ctiid.338647
- https://vuldb.com/?id.338647
- https://vuldb.com/?submit.722426
Affected products (2)
- cpe:2.3:o:edimax:br-6208ac_firmware:1.02:*:*:*:*:*:*:*
- cpe:2.3:o:edimax:br-6208ac_firmware:1.03:*:*:*:*:*:*:*
More vulnerabilities in Edimax Br-6208ac Firmware
- CVE-2025-70161 — Critical (CVSS 9.8): EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly…
- CVE-2025-15256 — High (CVSS 7.3): A vulnerability was identified in Edimax BR-6208AC 1.02/1.03. Affected is the function formStaDrvSetup of the file…
- CVE-2026-1972 — Medium (CVSS 5.3): A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2.…
- CVE-2025-14910 — Medium (CVSS 4.3): A vulnerability was detected in Edimax BR-6208AC 1.02. This impacts the function handle_retr of the component FTP…
- CVE-2025-15258 — Low (CVSS 3.5): A weakness has been identified in Edimax BR-6208AC 1.02/1.03. Affected by this issue is the function formALGSetup of…
All CVEs affecting Edimax Br-6208ac Firmware →
Other CWE-77 (Command Injection) vulnerabilities
- CVE-2025-70518 — Critical (CVSS 10.0): The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied…
- CVE-2026-105484 — Critical (CVSS 10.0): A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the…
- CVE-2026-105134 — Critical (CVSS 10.0): A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file…
- CVE-2026-102240 — Critical (CVSS 10.0): A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file…
- CVE-2026-101076 — Critical (CVSS 10.0): A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file…
- CVE-2026-101075 — Critical (CVSS 10.0): A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of…