Executive brief
A security vulnerability exists in the Edimax EW-7478APC router, a device used to provide wireless networking and internet connectivity. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a complete loss of internet service or unauthorized access to the network traffic passing through the router.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in the Edimax EW-7478APC router firmware version 1.04. The flaw is located within the 'formPPPoESetup' function of the '/goform/formPPPoESetup' component, which handles POST requests for PPPoE configuration. By sending a malicious POST request with an oversized 'pppUserName' argument, a remote attacker with low privileges can trigger the overflow. This can lead to arbitrary code execution or a denial-of-service (DoS) condition. Public exploit code is reportedly available, and the vendor has not yet provided a patch.
Affected products
- Edimax EW-7478APC 1.04
Timeline
- 2026-06-29: advisory: NVD publication date
- 2026-06-29: disclosed: Public disclosure of the vulnerability and exploit