Junglewise Threat Intelligence

CVE-2026-10165: Edimax BR-6478AC stack overflow in formWanTcpipSetup

CVE-2026-10165 · Severity: high · CVSS 8.8 · Published 2026-05-31

Technologies: Edimax BR-6478AC. Vendors: Edimax.

Executive brief

A security vulnerability has been identified in the Edimax BR-6478AC router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to crash the device or potentially take full control of its operations. This could lead to a complete loss of internet service for the network or unauthorized access to data passing through the router.

Technical details

A stack-based buffer overflow vulnerability exists in the Edimax BR-6478AC router version 1.23 within the POST request handler. The flaw is located in the 'formWanTcpipSetup' function in the '/goform/formWanTcpipSetup' file. By sending a specially crafted POST request with a manipulated 'pppUserName' argument, a remote attacker with low privileges can trigger the overflow. This can lead to arbitrary code execution or a system crash (denial of service). Public exploit code is reportedly available, increasing the risk of exploitation.

Affected products

  • Edimax BR-6478AC 1.23

Timeline

  • 2026-05-31: advisory: Initial disclosure by VulDB and NVD

References

Related threats