Junglewise Threat Intelligence

CVE-2026-9401: Edimax BR-6675nD buffer overflow in formWanTcpipSetup

CVE-2026-9401 · Severity: high · CVSS 8.8 · Published 2026-05-24

Technologies: Edimax BR-6675nD. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax BR-6675nD wireless router, a device used to provide internet connectivity and networking for homes and small offices. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a complete loss of internet service, unauthorized access to the local network, or the theft of sensitive data passing through the router.

Technical details

A classic buffer overflow (CWE-120) exists in the Edimax BR-6675nD firmware version 1.12. The vulnerability is located within the 'formWanTcpipSetup' function in the '/goform/formWanTcpipSetup' file, which handles POST requests for WAN configuration. By providing an overly long string to the 'pppUserName' argument, an attacker can overflow a memory buffer. This attack can be performed over the network, though it typically requires low-level authentication (PR:L). Successful exploitation could lead to remote code execution (RCE) or a denial of service (DoS) condition. As of the advisory date, the vendor has not responded to disclosure attempts, and no official patch is available.

Affected products

  • Edimax BR-6675nD 1.12

Timeline

  • 2026-05-24: disclosed: Exploit disclosed to the public
  • 2026-05-24: advisory: NVD published the CVE record

References

Related threats