Executive brief
A security vulnerability has been identified in the Edimax EW-7478APC router, a device used to provide wireless networking and internet connectivity. An attacker could exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted request to the router's configuration interface. This could lead to a complete loss of internet availability and unauthorized access to the network traffic passing through the device.
Technical details
A stack-based buffer overflow vulnerability exists in the Edimax EW-7478APC router version 1.04. The flaw is located within the 'formL2TPSetup' function of the '/goform/formL2TPSetup' component, which handles POST requests. By providing a long string to the 'L2TPUserName' argument, an attacker can overflow the stack buffer. This attack can be launched remotely, though it typically requires low-level authentication (PR:L). Successful exploitation could lead to remote code execution (RCE) or a denial of service (DoS) condition. As of the advisory date, the vendor has not responded to the disclosure, and no official patch is available.
Affected products
- Edimax EW-7478APC 1.04
Timeline
- 2026-06-29: advisory: NVD publication date
- 2026-06-29: disclosed: Public disclosure of the exploit