Junglewise Threat Intelligence

CVE-2026-9294: Edimax BR-6428NS buffer overflow in formWanTcpipSetup

CVE-2026-9294 · Severity: high · CVSS 8.8 · Published 2026-05-23

Technologies: Edimax BR-6428nS. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax BR-6428NS wireless router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a complete loss of internet service or unauthorized access to the network traffic passing through the router.

Technical details

A stack-based buffer overflow vulnerability exists in the Edimax BR-6428NS router version 1.10. The flaw is located within the 'formWanTcpipSetup' function in the '/goform/formWanTcpipSetup' component, which handles POST requests for WAN configuration. By manipulating the 'pppUserName' argument with an overly long string, a remote attacker with low privileges can trigger a memory corruption. This can result in arbitrary code execution or a denial of service (system crash). While the vendor was notified, no patch has been released, and public exploit code is reportedly available.

Affected products

  • Edimax BR-6428NS 1.10

Timeline

  • 2026-05-23: advisory: Initial disclosure by VulDB and NVD
  • 2026-05-23: disclosed: Public exploit code made available

References

Related threats