CVE-2026-9295: Edimax BR-6428NS POST Request formWirelessTbl buffer overflow
A security flaw has been discovered in Edimax BR-6428NS 1.10. This affects the function formWirelessTbl of the file /goform/formWirelessTbl of the component POST Request Handler. Performing a manipulation of the argument vapurl results in buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9295?
CVE-2026-9295 has a high severity rating of 8.8.
How does CVE-2026-9295 affect the Edimax BR-6428NS?
CVE-2026-9295 affects the function formWirelessTbl in the Edimax BR-6428NS by allowing a remote attacker to exploit a buffer overflow via manipulated arguments.
What is the primary vector for the CVE-2026-9295 vulnerability?
The primary attack vector for CVE-2026-9295 is remote, allowing attackers to exploit the vulnerability without local access.
What are the potential consequences of exploiting CVE-2026-9295?
Exploiting CVE-2026-9295 can lead to denial of service or unauthorized access due to the buffer overflow.
How can users protect against CVE-2026-9295 vulnerabilities?
Users should apply security patches from Edimax to address the CVE-2026-9295 vulnerability.