CVE-2025-28146 | Edimax BR-6478AC 1.0.15 formLtefotaUpgradeQuectel fota_url command injection
A vulnerability classified as critical was found in Edimax BR-6478AC 1.0.15. Affected by this vulnerability is the function fota_url of the file /boafrm/formLtefotaUpgradeQuectel. The manipulation leads to command injection.
This vulnerability is known as CVE-2025-28146. The attack needs to be done within the local network. There is no exploit available.