CVE-2026-10125: Edimax BR-6478AC POST Request formPPPoESetup stack-based overflow
A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. The manipulation of the argument pppUserName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable remote web/administration access (block WAN access) so the /goform/formPPPoESetup POST endpoint cannot be reached from untrusted networks.
Edimax BR-6478AC web interface (POST request handler) remote_management = disabled - Configuration
If the device supports disabling or restricting web-based PPPoE setup, disable the formPPPoESetup endpoint or restrict access to it to trusted management hosts only.
Edimax BR-6478AC PPPoE configuration formPPPoESetup endpoint = disabled or restricted - Compensating control
Place the device behind a firewall or apply ACLs to block inbound HTTP/HTTPS and management traffic from untrusted networks; restrict management access to trusted IP addresses only.
- Compensating control
Isolate the device on a management VLAN or otherwise segregate it from general network and Internet access to reduce remote attack surface.
- Operational
Monitor logs for POST requests to /goform/formPPPoESetup and for indicators of exploitation; if an attempt or compromise is detected, isolate the device immediately and conduct incident response.
- Operational
Remove or take the device offline or replace it until a vendor-supplied patch or fixed firmware is published (exploit is publicly available and the vulnerability is remotely exploitable).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10125?
CVE-2026-10125 has a severity rating of 8.8, which is classified as high.
How do I fix CVE-2026-10125?
To remediate CVE-2026-10125, update the Edimax BR-6478AC to the latest firmware version provided by the manufacturer.
What component is affected by CVE-2026-10125?
CVE-2026-10125 affects the POST Request Handler, specifically the formPPPoESetup function in the Edimax BR-6478AC router.
What type of vulnerability is CVE-2026-10125?
CVE-2026-10125 is a stack-based buffer overflow vulnerability.
What can an attacker achieve by exploiting CVE-2026-10125?
Exploitation of CVE-2026-10125 could allow an attacker to execute arbitrary code or cause a denial of service.