Executive brief
A security vulnerability exists in the Edimax EW-7438RPn Wi-Fi extender, a device used to expand wireless network coverage. An attacker can exploit a flaw in the logout process to crash the device or potentially take full control of it. This could lead to a complete loss of internet connectivity for users relying on the extender and may allow unauthorized access to the local network.
Technical details
A stack-based buffer overflow vulnerability exists in the 'webs' binary of the Edimax EW-7438RPn Wi-Fi extender (firmware version 1.31). The vulnerability is located in the 'formLogout' function within the '/goform/formLogout' endpoint. The 'submit-url' POST parameter is copied into a local stack variable without adequate bounds checking. A remote attacker with low privileges (authenticated) can provide an excessively long string to overwrite the return address on the stack. This can result in a Denial of Service (system crash) or arbitrary code execution. As of the advisory date, the vendor has not responded to the disclosure.
Affected products
- Edimax EW-7438RPn 1.31
Timeline
- 2026-05-25: disclosed: Public disclosure of the vulnerability and PoC
- 2026-05-25: advisory: CVE-2026-9479 published