Junglewise Threat Intelligence

CVE-2026-9460: Edimax EW-7438RPn stack buffer overflow in formAccept

CVE-2026-9460 · Severity: high · CVSS 8.8 · Published 2026-05-25

Technologies: Edimax EW-7438RPn. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax EW-7438RPn Wi-Fi extender, a device used to expand wireless network coverage. An attacker can send a specially crafted web request to the device to cause it to crash or potentially take full control of the hardware. This could lead to a complete loss of internet connectivity through the extender and allow unauthorized access to the local network.

Technical details

A stack-based buffer overflow vulnerability exists in the 'formAccept' function within the '/goform/formAccept' endpoint of the Edimax EW-7438RPn (firmware version 1.31). The vulnerability is caused by a lack of bounds checking on the 'submit-url' POST parameter, which is copied directly into a fixed-size local stack buffer. A remote attacker with low privileges (authenticated access) can exploit this by sending an overly long string in the 'submit-url' argument, overwriting the function's return address. This can result in a persistent denial of service (device crash) or arbitrary code execution. A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Edimax EW-7438RPn 1.31

Timeline

  • 2026-05-25: advisory: Initial disclosure by VulDB and NVD
  • 2026-05-25: disclosed: Public PoC released on GitHub

References

Related threats