CVE-2026-9294: Edimax BR-6428NS POST Request formWanTcpipSetup buffer overflow
A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manipulation of the argument pppUserName leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Edimax BR-6428NSfrom your environment.Remove or physically disconnect the device from the network if it cannot be isolated or otherwise secured.
- Configuration
Disable remote/WAN web administration to prevent remote POST requests (such as to /goform/formWanTcpipSetup) from untrusted networks.
Edimax BR-6428NS web administration remote_admin_access = disabled - Compensating control
Restrict access to the device management interface to trusted IPs/networks using network ACLs or firewall rules; block management ports from the WAN.
- Operational
Monitor logs for attempts targeting /goform/formWanTcpipSetup or suspicious POST requests; isolate and investigate any compromised devices, and apply vendor-supplied updates if and when they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9294?
The severity of CVE-2026-9294 is classified as high with a score of 8.8.
How do I fix CVE-2026-9294?
To mitigate CVE-2026-9294, update the Edimax BR-6428NS to the latest firmware version provided by the manufacturer.
What type of vulnerability is CVE-2026-9294?
CVE-2026-9294 is a buffer overflow vulnerability affecting the POST Request Handler in Edimax BR-6428NS.
What could an attacker achieve by exploiting CVE-2026-9294?
Exploiting CVE-2026-9294 could allow an attacker to execute arbitrary code on the device due to the buffer overflow.
On which device is CVE-2026-9294 found?
CVE-2026-9294 is found on the Edimax BR-6428NS version 1.10.