Junglewise Threat Intelligence

CVE-2026-9346: Edimax EW-7438RPn buffer overflow in formWirelessTbl

CVE-2026-9346 · Severity: high · CVSS 8.8 · Published 2026-05-24

Technologies: Edimax EW-7438RPn. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax EW-7438RPn Wi-Fi extender, a device used to expand wireless network coverage. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a total loss of internet connectivity for users relying on the extender and may allow unauthorized access to the local network.

Technical details

A stack-based buffer overflow exists in the 'webs' binary of the Edimax EW-7438RPn firmware (up to version 1.31). The vulnerability is located within the 'formWirelessTbl' function in the '/goform/formWirelessTbl' handler. The root cause is the unsafe copying of the 'submit-url' POST parameter into a fixed-size local stack buffer without adequate bounds checking. A remote attacker with low-privileged credentials can exploit this by sending an oversized string in the 'submit-url' argument, allowing them to overwrite the return address and achieve arbitrary code execution or cause a device crash (DoS). Public exploit code (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Edimax EW-7438RPn up to 1.31

Timeline

  • 2026-05-24: advisory: Initial disclosure via VulDB and NVD

References

Related threats