Executive brief
A security vulnerability exists in the Edimax BR-6478AC router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to take control of the device or cause it to crash by sending a specially crafted request to the router's configuration interface. This could lead to a complete loss of internet connectivity or unauthorized access to the local network.
Technical details
A stack-based buffer overflow vulnerability exists in the Edimax BR-6478AC router version 1.23. The flaw is located within the 'formL2TPSetup' function in the '/goform/formL2TPSetup' component, which handles POST requests for L2TP configuration. By providing an excessively long string to the 'L2TPUserName' parameter, a remote authenticated attacker can trigger a buffer overflow. This can lead to arbitrary code execution or a denial of service (DoS) condition. While the attack requires network reachability and low-level authentication, an exploit has been publicly disclosed. As of the advisory date, the vendor has not provided a patch.
Affected products
- Edimax BR-6478ACV2 1.23
Timeline
- 2026-05-25: advisory: Vulnerability disclosed via VulDB and NVD
- 2026-05-25: disclosed: Public exploit details released