A vulnerability was found in Edimax EW-7478APC 1.04. It has been declared as critical. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipulation of the argument pppUserName/pptpUserName/L2TPUserName can lead to command injection.

This vulnerability appears as CVE-2026-19962. The attack may be performed from remote. In addition, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.