Junglewise Threat Intelligence

CVE-2026-9345: Edimax EW-7438RPn buffer overflow in formWizSurvey

CVE-2026-9345 · Severity: high · CVSS 8.8 · Published 2026-05-24

Technologies: Edimax EW-7438RPn. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax EW-7438RPn Wi-Fi extender, a device used to expand wireless network coverage. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending specially crafted network requests. This could lead to a complete loss of internet connectivity through the extender and unauthorized access to the device's settings.

Technical details

A stack-based buffer overflow vulnerability exists in the 'webs' binary of the Edimax EW-7438RPn extender (firmware up to 1.31). The vulnerability is located in the 'formWizSurvey' function within the '/goform/formWizSurvey' endpoint. The application fails to validate the length of several parameters, including 'ssid', 'manualssid', 'ip', 'mask', and 'gateway', before copying them into fixed-size stack buffers. A remote attacker with low privileges (authenticated) can provide overly long strings for these arguments to overwrite the function's return address. This can result in a denial of service (system crash) or arbitrary code execution. A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Edimax EW-7438RPn up to 1.31

Timeline

  • 2026-05-23: disclosed: Initial disclosure via VulDB and GitHub PoC
  • 2026-05-24: advisory: NVD publication date

References

Related threats