Executive brief
A security vulnerability exists in the Edimax BR-6478AC router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending specially crafted data to the router's management interface. This could lead to a complete loss of internet service or unauthorized access to the network traffic passing through the router.
Technical details
A stack-based buffer overflow vulnerability exists in the Edimax BR-6478AC router version 1.23. The flaw is located within the 'formUSBAccount' function in the '/goform/formUSBAccount' component, which handles POST requests. By providing overly long strings in the 'UserName' or 'Password' parameters, an attacker can trigger a buffer overflow. This vulnerability is reachable over the network; while it requires low-level authentication (PR:L), it can lead to full system compromise (RCE) or a denial of service (DoS). Public exploit details have been disclosed.
Affected products
- Edimax BR-6478AC 1.23
Timeline
- 2026-05-31: advisory: NVD publication date
- 2026-05-31: disclosed: Public disclosure of the exploit