Executive brief
A security vulnerability exists in the Edimax BR-6478AC wireless router, a device used to provide internet connectivity and networking for homes and small offices. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a complete loss of internet service and unauthorized access to the network's management interface.
Technical details
A stack-based buffer overflow vulnerability exists in the Edimax BR-6478AC router version 1.23. The flaw is located within the 'formiNICSiteSurvey' function in the '/goform/formiNICSiteSurvey' component, which handles POST requests. By manipulating the 'selSSID' argument, a remote attacker with low privileges can trigger a buffer overflow. This can lead to arbitrary code execution or a denial of service (DoS) condition. Public exploit code is reportedly available, and the vendor has not yet provided a patch or response.
Affected products
- Edimax BR-6478AC 1.23
Timeline
- 2026-05-25: disclosed: Public disclosure of the vulnerability
- 2026-05-25: advisory: CVE-2026-9442 published