Executive brief
A security vulnerability exists in the Edimax BR-6675nD wireless router. An attacker can exploit this flaw to cause a system crash or potentially take full control of the device by sending a specially crafted network request. This could lead to a complete loss of internet connectivity or unauthorized access to the local network.
Technical details
A stack-based buffer overflow vulnerability exists in the Edimax BR-6675nD router version 1.12. The flaw is located within the 'formsetPPPoE' function in the '/goform/formsetPPPoE' file, which serves as a POST request handler. By manipulating the 'pppUserName' argument, a remote attacker with low privileges can trigger the overflow. This occurs due to improper restriction of operations within the bounds of a memory buffer (CWE-119/CWE-120). Successful exploitation can lead to remote code execution or a complete system crash. As of the advisory date, the vendor has not responded to disclosure attempts, and no patch is currently available.
Affected products
- Edimax BR-6675nD 1.12
Timeline
- 2026-05-24: advisory: Initial disclosure of the vulnerability
- 2026-05-24: disclosed: Exploit code made public