Junglewise Threat Intelligence

CVE-2026-10125: Edimax BR-6478AC stack overflow in formPPPoESetup

CVE-2026-10125 · Severity: high · CVSS 8.8 · Published 2026-05-30

Technologies: Edimax BR-6478AC. Vendors: Edimax.

Executive brief

A security vulnerability has been identified in the Edimax BR-6478AC wireless router, a device used to provide internet connectivity and networking for homes and small offices. An attacker can exploit this flaw to gain unauthorized control over the device by sending a specially crafted web request. This could lead to a complete disruption of internet services, interception of network traffic, or further attacks on other devices connected to the local network.

Technical details

A stack-based buffer overflow vulnerability exists in the Edimax BR-6478AC router firmware version 1.23. The flaw is located within the 'formPPPoESetup' function in the '/goform/formPPPoESetup' component, which handles POST requests for PPPoE configuration. By manipulating the 'pppUserName' argument, a remote attacker with low privileges can overflow the stack buffer. This can lead to remote code execution (RCE) or a denial of service (DoS) condition. While the attack requires network reachability and basic authentication, a public exploit is reportedly available.

Affected products

  • Edimax BR-6478AC 1.23

Timeline

  • 2026-05-30: disclosed: Initial public disclosure of the vulnerability.
  • 2026-05-30: advisory: NVD published the CVE record.

References

Related threats