Junglewise Threat Intelligence

CVE-2026-13562: Edimax EW-7478APC buffer overflow in formiNICSiteSurvey

CVE-2026-13562 · Severity: high · CVSS 8.8 · Published 2026-06-29

Technologies: Edimax EW-7478APC. Vendors: Edimax.

Executive brief

A security vulnerability has been identified in the Edimax EW-7478APC wireless access point. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a complete loss of network connectivity or unauthorized access to the device's management functions. Currently, there is no official fix from the manufacturer.

Technical details

A classic buffer overflow (CWE-120/CWE-119) exists in the Edimax EW-7478APC firmware version 1.04. The vulnerability is located within the formiNICSiteSurvey function in the /goform/formiNICSiteSurvey file, which handles POST requests. By manipulating the 'selSSID' argument, a remote attacker with low privileges can trigger a memory corruption. This can lead to arbitrary code execution or a denial of service (DoS) condition. Public exploit code is reportedly available, and the vendor has not responded to disclosure attempts.

Affected products

  • Edimax EW-7478APC 1.04

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: advisory: NVD publication date

References

Related threats