Executive brief
A security vulnerability exists in the Edimax BR-6428NS wireless router, a device used to provide internet connectivity and networking for homes and small offices. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted request to the router's configuration interface. This could lead to a complete loss of internet service or unauthorized access to the local network.
Technical details
A stack-based buffer overflow vulnerability exists in the Edimax BR-6428NS router version 1.10. The flaw is located within the 'formPPTPSetup' function in the '/goform/formPPTPSetup' file, which handles POST requests for PPTP VPN configuration. Specifically, the 'pptpUserName' argument is processed without adequate bounds checking, allowing an attacker to overwrite memory. While the attack requires low-level authentication (PR:L), it can be executed over the network. Successful exploitation could lead to remote code execution (RCE) or a denial of service (DoS) condition. As of the advisory date, the vendor has not responded to disclosure attempts, and no official patch is available.
Affected products
- Edimax BR-6428NS 1.10
Timeline
- 2026-05-18: advisory: Initial disclosure by VulDB and NVD
- 2026-05-18: disclosed: Public exploit disclosed to the public