Executive brief
A security vulnerability has been identified in the Edimax EW-7478APC wireless access point. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a complete loss of network connectivity or unauthorized access to the device's management functions. Currently, there is no official fix from the manufacturer.
Technical details
A classic buffer overflow (CWE-120/CWE-119) exists in the Edimax EW-7478APC firmware version 1.04. The vulnerability is located within the formiNICSiteSurvey function in the /goform/formiNICSiteSurvey file, which handles POST requests. By manipulating the 'selSSID' argument, a remote attacker with low privileges can trigger a memory corruption. This can lead to arbitrary code execution or a denial of service (DoS) condition. Public exploit code is reportedly available, and the vendor has not responded to disclosure attempts.
Affected products
- Edimax EW-7478APC 1.04
Timeline
- 2026-06-29: disclosed
- 2026-06-29: advisory: NVD publication date