Junglewise Threat Intelligence

CVE-2026-10126: Edimax BR-6478AC buffer overflow in formQoS

CVE-2026-10126 · Severity: high · CVSS 8.8 · Published 2026-05-30

Technologies: Edimax BR-6478AC. Vendors: Edimax.

Executive brief

A security vulnerability has been identified in the Edimax BR-6478AC router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to crash the device or potentially take full control of the router's operations. This could lead to a complete loss of internet access for connected users or allow an attacker to intercept network traffic.

Technical details

A stack-based buffer overflow vulnerability exists in the Edimax BR-6478AC router, specifically within the 'formQoS' function located in the '/goform/formQoS' file. The vulnerability is triggered by insufficient validation of the 'selSSID' argument during a POST request. A remote attacker with low-level authentication can exploit this by providing an overly long string to the affected parameter, leading to memory corruption. This can result in a denial-of-service (DoS) condition or remote code execution (RCE). Public exploit code has been released for this vulnerability.

Affected products

  • Edimax BR-6478AC 1.23

Timeline

  • 2026-05-30: disclosed: Vulnerability disclosed and added to NVD dataset.
  • 2026-05-30: advisory

References

Related threats