Junglewise Threat Intelligence

CVE-2026-9481: Edimax EW-7438RPn stack overflow in formStats

CVE-2026-9481 · Severity: high · CVSS 8.8 · Published 2026-05-25

Technologies: Edimax EW-7438RPn. Vendors: Edimax.

Executive brief

A security vulnerability exists in the Edimax EW-7438RPn Wi-Fi extender that could allow an attacker to take control of the device. By sending a specially crafted web request, an attacker can cause the device to crash or potentially execute malicious code. This could lead to a total loss of network connectivity through the extender or unauthorized access to the device's settings and traffic.

Technical details

A stack-based buffer overflow vulnerability exists in the 'webs' binary of the Edimax EW-7438RPn Wi-Fi extender (firmware version 1.31). The flaw is located within the 'formStats' function in the '/goform/formStats' endpoint. The 'submit-url' POST parameter is copied into a local stack buffer without adequate length validation. An attacker with network access and basic authentication can provide an overly long string to overwrite the function's return address. This can result in a persistent denial of service (device crash) or arbitrary code execution. A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Edimax EW-7438RPn 1.31

Timeline

  • 2026-05-25: advisory: Initial disclosure and CVE assignment
  • 2026-05-25: disclosed: Public PoC released on GitHub

References

Related threats