Executive brief
A security vulnerability exists in the Edimax BR-6478AC V2 wireless router. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a complete loss of internet connectivity or unauthorized access to the network traffic passing through the router.
Technical details
A stack-based buffer overflow vulnerability exists in the Edimax BR-6478AC V2 router running firmware version 1.23. The flaw is located within the formWlSiteSurvey function in the /goform/formWlSiteSurvey component, which handles POST requests. By manipulating the 'selSSID' argument, a remote attacker with low-level authentication can trigger the overflow. This can lead to arbitrary code execution or a system crash (denial of service). Although the vendor was notified, no patch has been released, and public exploit details are available.
Affected products
- Edimax BR-6478AC V2 1.23
Timeline
- 2026-06-21: disclosed: Public disclosure of the vulnerability and exploit details.
- 2026-06-21: advisory