Junglewise Threat Intelligence

CVE-2026-12806: Edimax BR-6478AC V2 buffer overflow in formWlSiteSurvey

CVE-2026-12806 · Severity: high · CVSS 8.8 · Published 2026-06-21

Technologies: Edimax BR-6478AC V2. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax BR-6478AC V2 wireless router. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a complete loss of internet connectivity or unauthorized access to the network traffic passing through the router.

Technical details

A stack-based buffer overflow vulnerability exists in the Edimax BR-6478AC V2 router running firmware version 1.23. The flaw is located within the formWlSiteSurvey function in the /goform/formWlSiteSurvey component, which handles POST requests. By manipulating the 'selSSID' argument, a remote attacker with low-level authentication can trigger the overflow. This can lead to arbitrary code execution or a system crash (denial of service). Although the vendor was notified, no patch has been released, and public exploit details are available.

Affected products

  • Edimax BR-6478AC V2 1.23

Timeline

  • 2026-06-21: disclosed: Public disclosure of the vulnerability and exploit details.
  • 2026-06-21: advisory

References

Related threats