Junglewise Threat Intelligence

CVE-2026-9295: Edimax BR-6428NS buffer overflow in formWirelessTbl

CVE-2026-9295 · Severity: high · CVSS 8.8 · Published 2026-05-23

Technologies: Edimax BR-6428nS. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax BR-6428NS wireless router. An attacker can exploit this flaw to cause a system crash or potentially take full control of the device by sending a specially crafted web request. This could lead to a complete loss of internet connectivity for the network or unauthorized access to network traffic.

Technical details

A stack-based buffer overflow vulnerability exists in the Edimax BR-6428NS router version 1.10. The flaw is located within the 'formWirelessTbl' function in the '/goform/formWirelessTbl' component, which handles POST requests. By manipulating the 'vapurl' argument, a remote attacker with low privileges can trigger the overflow. This can lead to arbitrary code execution or a denial of service (DoS). A public exploit has been released, and as of the advisory date, the vendor has not provided a patch or responded to the disclosure.

Affected products

  • Edimax BR-6428NS 1.10

Timeline

  • 2026-05-23: advisory: Initial disclosure by VulDB and NVD
  • 2026-05-23: disclosed: Public exploit released

References

Related threats