Junglewise Threat Intelligence

CVE-2026-19959: Edimax EW-7478APC stack buffer overflow in WAN configuration

CVE-2026-19959 · Severity: critical · CVSS 9.9 · Published 2026-08-16

Technologies: Edimax EW-7478APC. Vendors: Edimax.

Executive brief

The Edimax EW-7478APC is a wireless access point and extender used in home and small-office networks. A remote attacker can crash the device or execute arbitrary code by sending a malicious configuration request that overflows an internal memory buffer, without requiring authentication. This could lead to service disruption or complete control over the device.

Technical details

A stack-based buffer overflow exists in the formWanTcpipSetup function of the /goform/formWanTcpipSetup endpoint in Edimax EW-7478APC version 1.04. The vulnerability is triggered by supplying an oversized value in the pppUserName argument, which is not properly validated before being copied onto the stack. The flaw is remotely exploitable without authentication and allows an unauthenticated attacker to achieve remote code execution or denial of service. Proof-of-concept exploit code has been publicly disclosed. No vendor patch has been provided at the time of advisory publication.

Affected products

  • Edimax EW-7478APC 1.04

Timeline

  • 2026-08-16: disclosed
  • other: Vendor contacted early but did not respond

References

Related threats