CVE-2025-34029HIGH 8.8EPSS p87.6%

CVE-2025-34029CVE-2025-34029

Description

An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscmd.asp form handler. The /goform/formSysCmd endpoint exposes a system command interface through the sysCmd parameter. A remote authenticated attacker can submit arbitrary shell commands directly, resulting in command execution as the root user. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-14 UTC.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS3.47% probability of exploitation · percentile 87.6% · 2026-06-19T12:03:05Z
Published2025-06-20
Last modified2025-11-20

Underlying weaknesses· 1

CWE-78

References

  1. https://vulncheck.com/advisories/edimax-ew-7438rpn-command-injections
  2. https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=32163
  3. https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/global/wi-fi_range_extenders_n300/ew-7438rpn_mini/
  4. https://www.exploit-db.com/exploits/48377

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')cwe-780%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-34024
CVE
CVE-2026-9480
CVE
CVE-2026-9346
CVE
CVE-2026-9460
CVE
CVE-2026-9482
CVE
CVE-2026-9426
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.