Junglewise Threat Intelligence

CVE-2026-9382: Edimax BR-6675nD buffer overflow in formPPTPSetup

CVE-2026-9382 · Severity: high · CVSS 8.8 · Published 2026-05-24

Technologies: Edimax BR-6675nD. Vendors: Edimax.

Executive brief

A security vulnerability has been identified in the Edimax BR-6675nD wireless router. This device is used to provide internet connectivity and network management for home and small office environments. An attacker could exploit this flaw to crash the device or potentially take full control of it, leading to a complete loss of internet service and unauthorized access to the local network.

Technical details

A stack-based buffer overflow vulnerability exists in the Edimax BR-6675nD router version 1.12. The flaw is located within the 'formPPTPSetup' function in the '/goform/formPPTPSetup' component, which handles POST requests for PPTP configuration. By sending a specially crafted POST request with a manipulated 'pptpUserName' argument, a remote attacker with low privileges can trigger the overflow. This can lead to arbitrary code execution or a denial of service (DoS). As of the disclosure date, the vendor has not responded to reports, and no official patch is available. Public exploit code is reportedly available.

Affected products

  • Edimax BR-6675nD 1.12

Timeline

  • 2026-05-24: advisory: Vulnerability disclosed by VulDB
  • 2026-05-24: disclosed: Exploit published publicly

References

Related threats