Junglewise Threat Intelligence

CVE-2026-13582: Edimax EW-7478APC buffer overflow in formUSBAccount

CVE-2026-13582 · Severity: high · CVSS 8.8 · Published 2026-06-29

Technologies: Edimax EW-7478APC. Vendors: Edimax.

Executive brief

A security vulnerability has been identified in the Edimax EW-7478APC router, a device used to provide wireless internet connectivity. An attacker can exploit a flaw in how the device handles USB account settings to potentially take control of the router or cause it to crash. This could lead to unauthorized access to the network, interception of data, or a complete loss of internet service for connected users.

Technical details

A classic buffer overflow (CWE-120) exists in the Edimax EW-7478APC firmware version 1.04. The vulnerability is located within the 'formUSBAccount' function of the '/goform/formUSBAccount' file, which serves as a POST request handler. By manipulating the 'UserName' or 'Password' arguments in a POST request, an attacker can overflow a memory buffer. This attack can be carried out remotely, though it typically requires low-level authentication (PR:L). Successful exploitation could lead to full system compromise or a denial of service. As of the advisory date, the vendor has not responded to disclosure attempts, and no patch is currently available.

Affected products

  • Edimax EW-7478APC 1.04

Timeline

  • 2026-06-29: advisory: Initial disclosure by VulDB/NVD
  • 2026-06-29: disclosed: Public exploit published

References

Related threats