CVE-2026-13583: Edimax EW-7478APC POST Request formUSBFolder buffer overflow
A vulnerability has been found in Edimax EW-7478APC 1.04. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. Such manipulation of the argument ShareName/SelectName leads to buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13583?
The severity of CVE-2026-13583 is rated high with a score of 8.8.
What type of vulnerability is CVE-2026-13583?
CVE-2026-13583 is classified as a buffer overflow vulnerability.
How can CVE-2026-13583 be exploited?
CVE-2026-13583 can be exploited remotely by manipulating the arguments ShareName/SelectName in a POST request.
How do I fix CVE-2026-13583?
To fix CVE-2026-13583, ensure that you update the Edimax EW-7478APC to the latest firmware version provided by the manufacturer.
What systems are affected by CVE-2026-13583?
The Edimax EW-7478APC version 1.04 is impacted by CVE-2026-13583.