Junglewise Threat Intelligence

CVE-2026-19961: Edimax EW-7478APC buffer overflow in wireless site survey

CVE-2026-19961 · Severity: critical · CVSS 9.9 · Published 2026-08-16

Technologies: Edimax EW-7478APC. Vendors: Edimax.

Executive brief

The Edimax EW-7478APC is a wireless access point used to extend network coverage in offices and homes. A buffer overflow vulnerability in its web management interface allows attackers to remotely crash the device or potentially execute malicious code, disabling network connectivity for all connected users. The exploit is publicly available and the vendor has not provided patches or acknowledgment.

Technical details

The vulnerability is a stack buffer overflow in the formWlSiteSurvey function within the /goform/formWlSiteSurvey endpoint of the Edimax EW-7478APC firmware version 1.04. The flaw is triggered by manipulating the selSSID parameter, which is not properly validated before being written to a fixed-size buffer. The attack is remotely exploitable without authentication, allowing an unauthenticated attacker to send a crafted request that overflows the buffer and potentially achieve remote code execution or denial of service. Public exploit code is available, and Edimax has not responded to responsible disclosure attempts or released a firmware patch.

Affected products

  • Edimax EW-7478APC 1.04

Timeline

  • 2026-08-16: disclosed: Vulnerability disclosed publicly; exploit code available
  • 2026-08-16: other: Vendor contacted but did not respond

References

Related threats