CVE-2025-1316
Edimax IC-7100 IP Camera
Published 5 Mar 2025 · updated 17 Jun 2026 · Analyzed
9.3 Critical · CVSS 4.0, hq.dhs.gov
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 19 Mar 2025, with a remediation deadline of 9 Apr 2025 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device
References
- www.cisa.gov/news-events/ics-advisories/icsa-25-063-08 · Mitigation, Third Party Advisory, US Government Resource
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-1316 · US Government Resource