Executive brief
A security vulnerability exists in the Edimax BR-6428NS wireless router. An attacker can exploit this flaw to cause a system crash or potentially take full control of the device by sending a specially crafted web request. This could lead to a complete loss of internet connectivity for the network or unauthorized access to network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the Edimax BR-6428NS router version 1.10. The flaw is located within the 'formWirelessTbl' function in the '/goform/formWirelessTbl' component, which handles POST requests. By manipulating the 'vapurl' argument, a remote attacker with low privileges can trigger the overflow. This can lead to arbitrary code execution or a denial of service (DoS). A public exploit has been released, and as of the advisory date, the vendor has not provided a patch or responded to the disclosure.
Affected products
- Edimax BR-6428NS 1.10
Timeline
- 2026-05-23: advisory: Initial disclosure by VulDB and NVD
- 2026-05-23: disclosed: Public exploit released