The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record
Check your router model and firmware version (look for BR-6478AC V3 and firmware 1.0.15; also verify if you use BR-6476AC).
If you are on BR-6478AC V3 firmware 1.0.15, upgrade to the latest Edimax firmware that fixes CVE-2025-28146 (confirm the fix with Edimax release notes or support).
If no fixed firmware is available yet, restrict access to the router from the internet (tighten firewall rules) and block/limit access to the affected web endpoint from untrusted networks.
If you must keep the router exposed, add application-level filtering (for example, a WAF or equivalent reverse-proxy filtering) to block requests attempting to manipulate fota_url.
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel
In plain language
Written by AI from the record
If you run an Edimax BR-6478AC V3 router on firmware 1.0.15 (and possibly Edimax BR-6476AC), an attacker could remotely trick the router into running malicious commands—so you should act to update or mitigate quickly.
CVE-2025-28146 is a remote command injection in Edimax BR-6478AC V3 firmware 1.0.15 via the fota_url parameter in /boafrm/formLtefotaUpgradeQuectel, enabling unauthenticated attackers to execute arbitrary system commands over the network.
If you're affected
Full router compromise
Network disruption
Data theft via the router
Ransomware pivot risk
What is it
This is a flaw where the router’s software can be tricked into running system-level commands based on a value sent in a web request (fota_url). In plain terms, it’s like someone finding a “phone home” feature on your router and turning it into a way to run code on the router itself. Because it’s network-based and doesn’t require a login, it can be abused remotely if the router can be reached.
Who is affected
This matters if you use an Edimax BR-6478AC V3 router running firmware 1.0.15. It may also be relevant to Edimax BR-6476AC based on the affected product list provided.
Actively reachable risk depends on whether an attacker can reach the router’s web interface/endpoint from the network—because the vulnerability does not require authentication, the key gate is network exposure (for example, the router being accessible from the internet or from an untrusted network).
How urgent is it
Treat this as urgent because the vulnerability allows remote attackers to execute arbitrary commands without authentication or user interaction. Even though no official KEV entry or public exploit code was found in the provided sources, the impact (router takeover) is severe and the issue is serious enough to warrant prompt mitigation or firmware update.
What to do — in detail
Confirm exposure and versions
Identify your exact router model (Edimax BR-6478AC V3 and/or Edimax BR-6476AC).
Record the current firmware version. The specific vulnerable firmware called out here is BR-6478AC V3 firmware 1.0.15.
Determine whether the router management/UI (and the affected path) is reachable from untrusted networks (internet or guest networks). Review router settings for remote administration, port forwarding, UPnP, or any public exposure.
Check for a fixed firmware
Contact Edimax support or check Edimax release notes for firmware that addresses CVE-2025-28146.
Upgrade only after confirming the release specifically fixes this issue (don’t rely on generic “security updates” language).
If you cannot upgrade immediately (mitigation)
Block inbound WAN access to router administration interfaces from the internet.
Remove any port-forwarding rules and disable UPnP if enabled.
Restrict access so that only trusted internal IPs can reach the router’s admin UI.
Add application-level filtering if available (WAF or reverse-proxy filtering) to block suspicious requests targeting fota_url (or the /boafrm/formLtefotaUpgradeQuectel endpoint) from the internet.
After upgrade / mitigation
Re-verify the router firmware version matches the fixed version.
Monitor router logs for repeated requests to the affected endpoint and unusual outbound behavior shortly after any exposure attempts.
Follow-up
If your business depends on the router for uptime, prioritize scheduling the upgrade window as soon as a confirmed fix is available from Edimax.
Technical context
Severity: very high risk in practice because it is a remote command injection (CWE-94) with unauthenticated access and no user interaction requirement.
Mechanism/attack vector: an attacker can supply malicious input via the fota_url parameter used by the endpoint /boafrm/formLtefotaUpgradeQuectel, leading to arbitrary system command execution on the router over the network.
Exploitation status: no KEV listing was provided and no public exploit code was found in the provided sources; however, due to the impact, treat exposure as high priority.
Likelihood: EPSS was reported as a prediction only and should not be relied upon as proof of exploitation.
What KEV means here: the provided findings state CVE-2025-28146 is not listed in the CISA KEV set, so there is no confirmed KEV-based exploitation signal from the provided data.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.