Executive brief
A security vulnerability has been identified in the Edimax EW-7478APC router, a device used to provide wireless networking and internet connectivity. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted request to the router's USB management interface. This could lead to a total loss of internet availability, unauthorized access to the local network, or the interception of sensitive data.
Technical details
A stack-based buffer overflow exists in the Edimax EW-7478APC firmware version 1.04 within the 'formUSBFolder' function of the POST request handler located at /goform/formUSBFolder. The vulnerability is triggered by insufficient validation of the 'ShareName' and 'SelectName' arguments. A remote attacker with low-level privileges (authenticated) can exploit this by sending a crafted POST request to the device. Successful exploitation can lead to arbitrary code execution or a denial-of-service (DoS) condition. Public exploit code has been disclosed, and the vendor has reportedly not responded to the disclosure.
Affected products
- Edimax EW-7478APC 1.04
Timeline
- 2026-06-29: advisory: NVD and VulDB published the vulnerability details.
- 2026-06-29: disclosed: Public exploit code has been disclosed.