Executive brief
A security vulnerability exists in the Edimax EW-7438RPn Wi-Fi extender, a device used to increase the range of wireless networks. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending specially crafted web requests. This could lead to a complete loss of internet connectivity through the extender and unauthorized access to the device's settings.
Technical details
A stack-based buffer overflow vulnerability exists in the 'webs' binary of the Edimax EW-7438RPn Wi-Fi extender (firmware version 1.31). The flaw is located within the 'formHwSet' function in the '/goform/formHwSet' handler. The function fails to validate the length of several input parameters, including 'Anntena', 'Mcs', 'regDomain', and others, before copying them into a fixed-size stack buffer. A remote attacker with low privileges (authenticated) can exploit this by sending a POST request with excessively long strings, overwriting the return address to achieve arbitrary code execution or a device crash (DoS). As of the advisory date, the vendor has not responded to disclosure attempts, and no patch is available.
Affected products
- Edimax EW-7438RPn 1.31
Timeline
- 2026-05-25: disclosed: Public disclosure of the vulnerability and PoC.
- 2026-05-25: advisory: CVE-2026-9426 published.