Executive brief
A vulnerability exists in the Edimax EW-7438RPn Wi-Fi extender that could allow an attacker to take control of the device. By sending a specially crafted web request to the device's management interface, an attacker can cause the system to crash or potentially execute malicious code. This could lead to a total loss of network connectivity or unauthorized access to the device's settings and traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the 'webs' binary of the Edimax EW-7438RPn firmware version 1.31. The flaw is located within the 'formWlSiteSurvey' function in the '/goform/formWlSiteSurvey' file. The vulnerability is triggered by failing to validate the length of the 'selSSID' and 'submit-url' HTTP POST parameters before copying them into a fixed-size stack buffer. A remote attacker with low privileges (authenticated access) can exploit this by sending an oversized string in these parameters to overwrite the return address on the stack, leading to arbitrary code execution or a persistent denial of service (device crash). A public exploit has been released, and the vendor has reportedly not responded to disclosure attempts.
Affected products
- Edimax EW-7438RPn 1.31
Timeline
- 2026-05-25: disclosed: Initial public disclosure and CVE assignment