Executive brief
A security vulnerability has been identified in the Edimax BR-6478AC router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to crash the device or potentially take full control of its operations. This could lead to a complete loss of internet service for the network or unauthorized access to data passing through the router.
Technical details
A stack-based buffer overflow vulnerability exists in the Edimax BR-6478AC router version 1.23 within the POST request handler. The flaw is located in the 'formWanTcpipSetup' function in the '/goform/formWanTcpipSetup' file. By sending a specially crafted POST request with a manipulated 'pppUserName' argument, a remote attacker with low privileges can trigger the overflow. This can lead to arbitrary code execution or a system crash (denial of service). Public exploit code is reportedly available, increasing the risk of exploitation.
Affected products
- Edimax BR-6478AC 1.23
Timeline
- 2026-05-31: advisory: Initial disclosure by VulDB and NVD