Junglewise Threat Intelligence

CVE-2026-10164: Edimax BR-6478AC buffer overflow in formUSBFolder

CVE-2026-10164 · Severity: high · CVSS 8.8 · Published 2026-05-31

Technologies: Edimax BR-6478AC. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax BR-6478AC wireless router, a device used to provide internet connectivity and network management. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted request to the router's USB management interface. This could lead to a total loss of network availability or unauthorized access to data passing through the router.

Technical details

A stack-based buffer overflow vulnerability exists in the Edimax BR-6478AC router firmware version 1.23. The flaw is located within the 'formUSBFolder' function in the '/goform/formUSBFolder' component of the web-based POST request handler. By manipulating the 'ShareName' or 'SelectName' parameters, a remote attacker with low-level privileges can trigger a buffer overflow. This can lead to remote code execution (RCE) or a denial of service (DoS) condition. The exploit has been disclosed publicly.

Affected products

  • Edimax BR-6478AC 1.23

Timeline

  • 2026-05-31: disclosed: Initial public disclosure and NVD publication.

References

Related threats