CVE-2026-96892
Received Received - Intake

Open Redirect Vulnerability in Edimax BR-6428nC Router

Vulnerability report for CVE-2026-96892, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: VulDB

Description

A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component goform Handler. Executing a manipulation of the argument submit-url can lead to open redirect. The attack may be launched remotely. The exploit has been published and may be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
edimax br-6428nc 1.16

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an open redirect flaw in the Edimax BR-6428nC router version 1.16. It exists in the websRedirect function of the goform Handler component. An attacker can manipulate the submit-url argument to redirect users to malicious sites. The exploit is publicly available and affects multiple endpoints. The vendor did not respond to the disclosure attempt.

Impact Analysis

This vulnerability allows attackers to trick users into visiting malicious websites by redirecting them from a trusted Edimax router page. Users may unknowingly disclose sensitive information like login credentials or install malware. The impact is limited as it requires user interaction (clicking a link) but could lead to phishing attacks or credential theft.

Compliance Impact

This vulnerability does not directly impact GDPR or HIPAA compliance as it is not a data breach or privacy violation. However, if exploited to steal user credentials or sensitive data, it could indirectly lead to non-compliance with these regulations. No specific compliance impact is documented in the provided context.

Mitigation Strategies

Immediately update the Edimax BR-6428nC firmware to the latest version if available. Disable remote access to the device if not required. Monitor network traffic for unusual redirects or requests to the submit-url parameter. Consider isolating the device from critical network segments until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96892. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart