CVE-2026-96892
Edimax BR-6428nC goform websRedirect redirect
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component goform Handler. Executing a manipulation of the argument submit-url can lead to open redirect. The attack may be launched remotely. The exploit has been published and may be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.
| CWE | CWE-601 |
| Vendor | edimax |
| Product | br-6428nc |
| Published | Sep 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for edimax br-6428nc
Be the first to know when new medium vulnerabilities affecting edimax br-6428nc are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Edimax / BR-6428nC
1.16
References
vuldb.com: https://vuldb.com/vuln/409175 vuldb.com: https://vuldb.com/vuln/409175/cti vuldb.com: https://vuldb.com/cve/CVE-2026-96892 vuldb.com: https://vuldb.com/submit/906338 tzh00203.notion.site: https://tzh00203.notion.site/Edimax-BR-6428nC-Open-Redirect-via-submit-url-33db5c52018a808a8c34c1cb68db7aab
Credits
๐ tian (VulDB User) VulDB CNA Team