Junglewise Threat Intelligence

CVE-2026-13564: Edimax EW-7478APC stack overflow in formPPPoESetup

CVE-2026-13564 · Severity: high · CVSS 8.8 · Published 2026-06-29

Technologies: Edimax EW-7478APC. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax EW-7478APC router, a device used to provide wireless networking and internet connectivity. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a complete loss of internet service or unauthorized access to the network traffic passing through the router.

Technical details

A stack-based buffer overflow vulnerability (CWE-121) exists in the Edimax EW-7478APC router firmware version 1.04. The flaw is located within the 'formPPPoESetup' function of the '/goform/formPPPoESetup' component, which handles POST requests for PPPoE configuration. By sending a malicious POST request with an oversized 'pppUserName' argument, a remote attacker with low privileges can trigger the overflow. This can lead to arbitrary code execution or a denial-of-service (DoS) condition. Public exploit code is reportedly available, and the vendor has not yet provided a patch.

Affected products

  • Edimax EW-7478APC 1.04

Timeline

  • 2026-06-29: advisory: NVD publication date
  • 2026-06-29: disclosed: Public disclosure of the vulnerability and exploit

References

Related threats