Junglewise Threat Intelligence

CVE-2026-13563: Edimax EW-7478APC stack buffer overflow in formL2TPSetup

CVE-2026-13563 · Severity: high · CVSS 8.8 · Published 2026-06-29

Technologies: Edimax EW-7478APC. Vendors: Edimax.

Executive brief

A security vulnerability has been identified in the Edimax EW-7478APC router, a device used to provide wireless networking and internet connectivity. An attacker could exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted request to the router's configuration interface. This could lead to a complete loss of internet availability and unauthorized access to the network traffic passing through the device.

Technical details

A stack-based buffer overflow vulnerability exists in the Edimax EW-7478APC router version 1.04. The flaw is located within the 'formL2TPSetup' function of the '/goform/formL2TPSetup' component, which handles POST requests. By providing a long string to the 'L2TPUserName' argument, an attacker can overflow the stack buffer. This attack can be launched remotely, though it typically requires low-level authentication (PR:L). Successful exploitation could lead to remote code execution (RCE) or a denial of service (DoS) condition. As of the advisory date, the vendor has not responded to the disclosure, and no official patch is available.

Affected products

  • Edimax EW-7478APC 1.04

Timeline

  • 2026-06-29: advisory: NVD publication date
  • 2026-06-29: disclosed: Public disclosure of the exploit

References

Related threats