Junglewise Threat Intelligence

CVE-2026-9344: Edimax EW-7438RPn stack overflow in formWpsStart

CVE-2026-9344 · Severity: high · CVSS 8.8 · Published 2026-05-24

Technologies: Edimax EW-7438RPn. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax EW-7438RPn Wi-Fi extender, a device used to expand wireless network coverage. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending specially crafted data to the device's management interface. This could lead to a total loss of internet connectivity through the extender and unauthorized access to the device's settings.

Technical details

A stack-based buffer overflow vulnerability exists in the 'webs' binary of Edimax EW-7438RPn firmware up to version 1.31. The vulnerability is located in the 'formWpsStart' function associated with the '/goform/formWpsStart' endpoint. The root cause is a failure to validate the length of the 'pinCode' and 'wlan-url' POST parameters before copying them into a fixed-size stack buffer. A remote attacker with low privileges (authenticated) can exploit this by sending an oversized string in these parameters, allowing for service disruption (DoS) or arbitrary code execution by overwriting the function's return address. A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Edimax EW-7438RPn up to 1.31

Timeline

  • 2026-05-24: advisory: Initial disclosure via VulDB and NVD
  • 2026-05-24: disclosed: Public PoC released on GitHub

References

Related threats