CVE-2025-22906: Edimax RE11S Firmware

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.

Affected products

  • Edimax RE11S Firmware: version 1.11 only

Published 2025-01-16. Last modified 2026-07-05.