Junglewise Threat Intelligence

CVE-2026-9459: Edimax EW-7438RPn stack overflow in formConnectionSetting

CVE-2026-9459 · Severity: high · CVSS 8.8 · Published 2026-05-25

Technologies: Edimax EW-7438RPn. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax EW-7438RPn Wi-Fi extender, a device used to boost wireless network coverage. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending specially crafted network requests. This could lead to a complete loss of internet connectivity through the extender or unauthorized access to the device's settings and traffic.

Technical details

A stack-based buffer overflow vulnerability exists in the 'webs' binary of the Edimax EW-7438RPn firmware version 1.31. The vulnerability is located within the 'formConnectionSetting' function in the '/goform/formConnectionSetting' file. The root cause is a failure to validate the length of the 'max_Conn' and 'timeOut' HTTP POST parameters before copying them into local stack variables. A remote attacker with low privileges (authenticated) can exploit this by sending an oversized string in these parameters, overwriting the function's return address to achieve arbitrary code execution or a device crash (DoS). A public exploit has been released, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Edimax EW-7438RPn 1.31

Timeline

  • 2026-05-25: disclosed: Initial public disclosure via VulDB and GitHub
  • 2026-05-25: advisory: CVE-2026-9459 published

References

Related threats