Junglewise Threat Intelligence

CVE-2026-9399: Edimax BR-6675nD buffer overflow in formsetPPPoE

CVE-2026-9399 · Severity: high · CVSS 8.8 · Published 2026-05-24

Technologies: Edimax BR-6675nD. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax BR-6675nD wireless router. An attacker can exploit this flaw to cause a system crash or potentially take full control of the device by sending a specially crafted network request. This could lead to a complete loss of internet connectivity or unauthorized access to the local network.

Technical details

A stack-based buffer overflow vulnerability exists in the Edimax BR-6675nD router version 1.12. The flaw is located within the 'formsetPPPoE' function in the '/goform/formsetPPPoE' file, which serves as a POST request handler. By manipulating the 'pppUserName' argument, a remote attacker with low privileges can trigger the overflow. This occurs due to improper restriction of operations within the bounds of a memory buffer (CWE-119/CWE-120). Successful exploitation can lead to remote code execution or a complete system crash. As of the advisory date, the vendor has not responded to disclosure attempts, and no patch is currently available.

Affected products

  • Edimax BR-6675nD 1.12

Timeline

  • 2026-05-24: advisory: Initial disclosure of the vulnerability
  • 2026-05-24: disclosed: Exploit code made public

References

Related threats