Junglewise Threat Intelligence

CVE-2026-13580: Edimax EW-7478APC buffer overflow in formQoS POST handler

CVE-2026-13580 · Severity: high · CVSS 8.8 · Published 2026-06-29

Technologies: Edimax EW-7478APC. Vendors: Edimax.

Executive brief

A security flaw has been identified in the Edimax EW-7478APC wireless router, a device used to provide internet connectivity and manage network traffic. An attacker can exploit this vulnerability to take control of the device or cause it to crash by sending a specially crafted web request. This could lead to a complete loss of internet service, unauthorized access to the local network, or the interception of data passing through the router.

Technical details

A stack-based buffer overflow vulnerability exists in the Edimax EW-7478APC firmware version 1.04. The flaw is located in the 'formQoS' function within the '/goform/formQoS' endpoint, which serves as a POST request handler. The vulnerability is triggered by insufficient validation of the 'selSSID' argument, allowing an attacker to overwrite memory on the stack. This is a remote, unauthenticated attack vector that can lead to arbitrary code execution or a device crash. While the vendor was notified, no patch has been released, and exploit details are publicly available.

Affected products

  • Edimax EW-7478APC 1.04

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: advisory: Public disclosure of the vulnerability and exploit details.

References

Related threats