Executive brief
A security vulnerability has been identified in the Edimax BR-6478AC wireless router, a device used to provide internet connectivity and networking for homes and small offices. An attacker can exploit this flaw to gain unauthorized control over the device by sending a specially crafted web request. This could lead to a complete disruption of internet services, interception of network traffic, or further attacks on other devices connected to the local network.
Technical details
A stack-based buffer overflow vulnerability exists in the Edimax BR-6478AC router firmware version 1.23. The flaw is located within the 'formPPPoESetup' function in the '/goform/formPPPoESetup' component, which handles POST requests for PPPoE configuration. By manipulating the 'pppUserName' argument, a remote attacker with low privileges can overflow the stack buffer. This can lead to remote code execution (RCE) or a denial of service (DoS) condition. While the attack requires network reachability and basic authentication, a public exploit is reportedly available.
Affected products
- Edimax BR-6478AC 1.23
Timeline
- 2026-05-30: disclosed: Initial public disclosure of the vulnerability.
- 2026-05-30: advisory: NVD published the CVE record.