📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global apt Financial Services, Banking HIGH 5h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Government and Federal Agencies CRITICAL 8h Global supply_chain Software Development and Open-Source Ecosystems HIGH 8h Global vulnerability Enterprise Software/SaaS MEDIUM 9h Global supply_chain Software Development HIGH 9h Global general Insurance/Risk Management HIGH 9h Global data_breach Enterprise Software / Information Technology CRITICAL 10h Global vulnerability Technology/Software CRITICAL 12h Global malware Social Media and Consumer Technology HIGH 12h Global apt Financial Services, Banking HIGH 5h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Government and Federal Agencies CRITICAL 8h Global supply_chain Software Development and Open-Source Ecosystems HIGH 8h Global vulnerability Enterprise Software/SaaS MEDIUM 9h Global supply_chain Software Development HIGH 9h Global general Insurance/Risk Management HIGH 9h Global data_breach Enterprise Software / Information Technology CRITICAL 10h Global vulnerability Technology/Software CRITICAL 12h Global malware Social Media and Consumer Technology HIGH 12h Global apt Financial Services, Banking HIGH 5h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Government and Federal Agencies CRITICAL 8h Global supply_chain Software Development and Open-Source Ecosystems HIGH 8h Global vulnerability Enterprise Software/SaaS MEDIUM 9h Global supply_chain Software Development HIGH 9h Global general Insurance/Risk Management HIGH 9h Global data_breach Enterprise Software / Information Technology CRITICAL 10h Global vulnerability Technology/Software CRITICAL 12h Global malware Social Media and Consumer Technology HIGH 12h
Vulnerabilities

CVE-2026-9441

Medium
CWE-74 — Weakness Type
Published: May 25, 2026  ·  Modified: May 28, 2026  ·  Source: NVD
CVSS v3
6.3
🔗 NVD Official
📄 Description (English)

A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. Performing a manipulation of the argument rootAPmac results in command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

🤖 AI Executive Summary

CVE-2026-9441 is a command injection vulnerability in Edimax BR-6478AC wireless router (v1.23) affecting the POST request handler. An unauthenticated attacker can manipulate the rootAPmac parameter to execute arbitrary commands remotely. With a CVSS score of 6.3 and public exploit availability, this poses a significant risk to organizations using this router model, particularly in network infrastructure and remote access scenarios.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 27, 2026 04:49
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations using Edimax BR-6478AC routers face significant risk, particularly: (1) Banking/SAMA-regulated entities using these devices in branch networks or remote access infrastructure; (2) Government agencies (NCA, NCSC) and critical infrastructure operators relying on these routers for network segmentation; (3) Telecommunications providers (STC, Mobily, Zain) using these devices in customer premises or network management; (4) Healthcare facilities using these routers for medical device connectivity; (5) Energy sector (ARAMCO, SEC) using these in SCADA/ICS environments. The lack of vendor response and public exploit availability elevates risk significantly.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Telecommunications Healthcare Energy and Utilities Critical Infrastructure Retail and E-commerce
⚖️ Saudi Risk Score (AI)
7.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all Edimax BR-6478AC v1.23 devices in your network using network scanning tools (nmap, Shodan queries)
2. Isolate affected devices from critical networks if possible, or implement network segmentation
3. Disable remote management features on the router's web interface
4. Change default credentials and implement strong authentication
5. Monitor for suspicious POST requests to /goform/formiNICbasic endpoint

COMPENSATING CONTROLS (No patch available):
1. Implement WAF/IPS rules to block POST requests with suspicious rootAPmac parameters containing shell metacharacters (;|&$(){}[]<>)
2. Restrict access to router management interface via firewall rules (whitelist only authorized IPs)
3. Deploy network segmentation to isolate router management traffic
4. Enable logging and alerting on all POST requests to /goform/formiNICbasic
5. Consider replacing with alternative router models from vendors with active security support

DETECTION RULES:
- Monitor for POST requests to /goform/formiNICbasic with rootAPmac parameter containing: backticks, $(), semicolons, pipes, ampersands, or other shell metacharacters
- Alert on any successful command execution patterns in router logs
- Track failed authentication attempts to router management interface
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع أجهزة Edimax BR-6478AC v1.23 في شبكتك باستخدام أدوات المسح (nmap، استعلامات Shodan)
2. عزل الأجهزة المتأثرة عن الشبكات الحرجة إن أمكن، أو تطبيق تقسيم الشبكة
3. تعطيل ميزات الإدارة البعيدة على واجهة الويب للجهاز
4. تغيير بيانات الاعتماد الافتراضية وتطبيق المصادقة القوية
5. مراقبة طلبات POST المريبة إلى نقطة نهاية /goform/formiNICbasic

الضوابط التعويضية (لا يوجد تصحيح متاح):
1. تطبيق قواعد WAF/IPS لحظر طلبات POST بمعاملات rootAPmac مريبة تحتوي على أحرف shell (;|&$(){}[]<>)
2. تقييد الوصول إلى واجهة إدارة الجهاز عبر قواعد جدار الحماية (قائمة بيضاء للعناوين المصرح بها فقط)
3. نشر تقسيم الشبكة لعزل حركة إدارة الجهاز
4. تفعيل التسجيل والتنبيهات على جميع طلبات POST إلى /goform/formiNICbasic
5. النظر في استبدال أجهزة التوجيه ببدائل من البائعين الذين يتمتعون بدعم أمان نشط
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 - Network access control and segmentation ECC 2024 A.5.2.1 - User access management and authentication ECC 2024 A.6.2.1 - Vulnerability management and patching ECC 2024 A.8.1.1 - Monitoring and logging of security events
🔵 SAMA CSF
SAMA CSF ID.AM-2 - Hardware and software assets are catalogued SAMA CSF PR.AC-1 - Access to physical and logical assets is managed SAMA CSF PR.IP-12 - A vulnerability management plan is developed and implemented SAMA CSF DE.CM-1 - The network is monitored to detect potential cybersecurity events
🟡 ISO 27001:2022
ISO 27001:2022 A.5.15 - Access control ISO 27001:2022 A.8.1 - Information security policies ISO 27001:2022 A.8.2 - Information security organization ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities
🟣 PCI DSS v4.0.1
PCI DSS 1.1 - Firewall configuration standards PCI DSS 2.1 - Change default vendor-supplied passwords PCI DSS 6.2 - Security patches and updates
📊 CVSS Score
6.3
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityL — Low / Local
📋 Quick Facts
Severity Medium
CVSS Score6.3
CWECWE-74
EPSS0.84%
Exploit No
Patch ✗ No
Published 2026-05-25
Source Feed nvd
🇸🇦 Saudi Risk Score
7.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-74
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.