CVE-2026-13580: Edimax EW-7478APC POST Request formQoS buffer overflow
A security vulnerability has been detected in Edimax EW-7478APC 1.04. This affects the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13580?
The severity of CVE-2026-13580 is rated high with a score of 8.8.
What type of vulnerability is CVE-2026-13580?
CVE-2026-13580 is a buffer overflow vulnerability found in the Edimax EW-7478APC.
How do I fix CVE-2026-13580?
To fix CVE-2026-13580, update the Edimax EW-7478APC to the latest firmware version provided by Edimax.
What component is affected by CVE-2026-13580?
CVE-2026-13580 affects the POST Request Handler in the formQoS function of the Edimax EW-7478APC.
Can CVE-2026-13580 be exploited remotely?
Yes, CVE-2026-13580 can be exploited remotely due to the nature of the buffer overflow vulnerability.