Executive brief
A security vulnerability exists in the Edimax BR-6675nD wireless router, a device used to provide internet connectivity and networking for homes and small offices. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a complete loss of internet service, unauthorized access to the local network, or the theft of sensitive data passing through the router.
Technical details
A stack-based buffer overflow vulnerability exists in the Edimax BR-6675nD router version 1.12. The flaw is located within the 'formWlSiteSurvey' function of the '/goform/formWlSiteSurvey' endpoint, which handles POST requests. By manipulating the 'selSSID' argument, a remote attacker with low privileges can trigger a buffer overflow. This occurs due to improper restriction of operations within the bounds of a memory buffer (CWE-119/CWE-120). Successful exploitation can lead to remote code execution or a complete system crash. Although the vendor was notified, no patch has been released, and exploit details are publicly available.
Affected products
- Edimax BR-6675nD 1.12
Timeline
- 2026-05-24: disclosed: Public disclosure of the vulnerability and exploit details.
- 2026-05-24: advisory: CVE-2026-9403 published.