Executive brief
A security vulnerability exists in the Edimax EW-7438RPn Wi-Fi extender, a device used to increase the range of wireless networks. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a complete loss of internet connectivity through the extender and unauthorized access to the device's settings.
Technical details
A stack-based buffer overflow vulnerability exists in the 'formRadius' function within the '/goform/formRadius' endpoint of the Edimax EW-7438RPn firmware version 1.31. The vulnerability is caused by the lack of bounds checking on the 'submit-url' POST parameter, which is copied directly into a fixed-size local stack buffer. An attacker with network access and low-level privileges (authenticated) can provide an overly long string to overwrite the function's return address. Successful exploitation can lead to a persistent denial of service (device crash) or remote code execution. As of the disclosure date, the vendor has not responded to reports or provided a patch.
Affected products
- Edimax EW-7438RPn 1.31
Timeline
- 2026-05-25: disclosed: Public disclosure of the vulnerability and PoC
- 2026-05-25: advisory