Executive brief
A security vulnerability has been identified in the Edimax BR-6478AC router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to crash the device or potentially take full control of the router's operations. This could lead to a complete loss of internet access for connected users or allow an attacker to intercept network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the Edimax BR-6478AC router, specifically within the 'formQoS' function located in the '/goform/formQoS' file. The vulnerability is triggered by insufficient validation of the 'selSSID' argument during a POST request. A remote attacker with low-level authentication can exploit this by providing an overly long string to the affected parameter, leading to memory corruption. This can result in a denial-of-service (DoS) condition or remote code execution (RCE). Public exploit code has been released for this vulnerability.
Affected products
- Edimax BR-6478AC 1.23
Timeline
- 2026-05-30: disclosed: Vulnerability disclosed and added to NVD dataset.
- 2026-05-30: advisory