Edimax EW-7438RPn formHwSet stack-based overflow
Description
A vulnerability was detected in Edimax EW-7438RPn 1.31. This affects the function formHwSet of the file /goform/formHwSet. The manipulation of the argument Anntena/Mcs/regDomain/nic0Addr/nic1Addr/wlanAddr/wanAddr/wlanSSID/wlanChan/initgain/txcck/txofdm/submit-url results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stack buffer overflow in Edimax EW-7438RPn 1.31's formHwSet function allows remote attackers to execute arbitrary code via crafted POST request.
Vulnerability
A stack-based buffer overflow vulnerability exists in the Edimax EW-7438RPn wireless extender with firmware version 1.31. The issue is located in the formHwSet function within the file /goform/formHwSet. The function does not validate the length of user-supplied input to parameters such as Anntena, Mcs, regDomain, nic0Addr, nic1Addr, wlanAddr, wanAddr, wlanSSID, wlanChan, initgain, txcck, txofdm, and submit-url. This allows an attacker to overflow a stack buffer by providing excessively long strings to these parameters [1].
Exploitation
An attacker can exploit this vulnerability by sending a crafted POST request to the /goform/formHwSet endpoint. The attacker does not need prior authentication if default credentials (admin:1234) are still in use, as shown in the public proof-of-concept. By manipulating any of the aforementioned parameters with a long string, the attacker can overwrite the return address on the stack, leading to arbitrary code execution. The attack can be performed remotely over the network [1].
Impact
Successful exploitation allows the attacker to execute arbitrary code on the device with elevated privileges, potentially gaining full control of the extender. This can lead to complete compromise of the device, including unauthorized access to network traffic, modification of settings, and denial of service [1].
Mitigation
As of the publication date, the vendor has not responded to the disclosure and no official patch is available. Users of the Edimax EW-7438RPn with firmware 1.31 should consider changing the default administrator password, disabling remote management features if possible, and monitoring for malicious activity. Replacing the device with a supported alternative is recommended [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: =1.31
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/wudipjq/my_vuln/blob/main/Edimax/vuln_10/10.mdmitreexploit
- vuldb.com/submit/813894mitrethird-party-advisory
- vuldb.com/vuln/365407mitrevdb-entrytechnical-description
- vuldb.com/vuln/365407/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.