CVE-2026-9294: Edimax BR-6428NS POST Request formWanTcpipSetup buffer overflow

Published May 23, 2026
·
Updated

A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manipulation of the argument pppUserName leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

1 affected component
Edimax BR-6428NS=1.10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Edimax BR-6428NS from your environment.

    Remove or physically disconnect the device from the network if it cannot be isolated or otherwise secured.

  2. Configuration

    Disable remote/WAN web administration to prevent remote POST requests (such as to /goform/formWanTcpipSetup) from untrusted networks.

    Edimax BR-6428NS web administration remote_admin_access = disabled
  3. Compensating control

    Restrict access to the device management interface to trusted IPs/networks using network ACLs or firewall rules; block management ports from the WAN.

  4. Operational

    Monitor logs for attempts targeting /goform/formWanTcpipSetup or suspicious POST requests; isolate and investigate any compromised devices, and apply vendor-supplied updates if and when they become available.

Event History

May 23, 2026
CVE Published
via MITRE·07:30 AM
Data Sourced
via MITRE·07:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Apr 28, 58520
Event
via FIRST·04:17 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-9294?

The severity of CVE-2026-9294 is classified as high with a score of 8.8.

2

How do I fix CVE-2026-9294?

To mitigate CVE-2026-9294, update the Edimax BR-6428NS to the latest firmware version provided by the manufacturer.

3

What type of vulnerability is CVE-2026-9294?

CVE-2026-9294 is a buffer overflow vulnerability affecting the POST Request Handler in Edimax BR-6428NS.

4

What could an attacker achieve by exploiting CVE-2026-9294?

Exploiting CVE-2026-9294 could allow an attacker to execute arbitrary code on the device due to the buffer overflow.

5

On which device is CVE-2026-9294 found?

CVE-2026-9294 is found on the Edimax BR-6428NS version 1.10.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203