Junglewise Threat Intelligence

CVE-2026-9443: Edimax BR-6478AC buffer overflow in formL2TPSetup

CVE-2026-9443 · Severity: high · CVSS 8.8 · Published 2026-05-25

Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax BR-6478AC router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to take control of the device or cause it to crash by sending a specially crafted request to the router's configuration interface. This could lead to a complete loss of internet connectivity or unauthorized access to the local network.

Technical details

A stack-based buffer overflow vulnerability exists in the Edimax BR-6478AC router version 1.23. The flaw is located within the 'formL2TPSetup' function in the '/goform/formL2TPSetup' component, which handles POST requests for L2TP configuration. By providing an excessively long string to the 'L2TPUserName' parameter, a remote authenticated attacker can trigger a buffer overflow. This can lead to arbitrary code execution or a denial of service (DoS) condition. While the attack requires network reachability and low-level authentication, an exploit has been publicly disclosed. As of the advisory date, the vendor has not provided a patch.

Affected products

  • Edimax BR-6478ACV2 1.23

Timeline

  • 2026-05-25: advisory: Vulnerability disclosed via VulDB and NVD
  • 2026-05-25: disclosed: Public exploit details released

References