CVE-2026-9425: Edimax EW-7438RPn formWlanMP stack-based overflow
A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The impacted element is the function formWlanMP of the file /goform/formWlanMP. The manipulation of the argument ateFunc/ateGain/ateTxCount/ateChan/ateRate/ateMacID/e2pTxPower1/e2pTxPower2/e2pTxPower3/e2pTxPower4/e2pTxPower5/e2pTxPower6/e2pTxPower7/e2pTx2Power1/e2pTx2Power2/e2pTx2Power3/e2pTx2Power4/e2pTx2Power5/e2pTx2Power6/e2pTx2Power7/ateTxFreqOffset/ateMode/ateBW/ateAntenna/e2pTxFreqOffset/e2pTxPwDeltaB/e2pTxPwDeltaG/e2pTxPwDeltaMix/e2pTxPwDeltaN/readE2P leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the ATE/MP test function (formWlanMP) on the device to prevent remote invocation of the vulnerable handler. If the firmware does not provide an explicit setting, remove or block access to the endpoint or disable any test/engineering modes in the device UI.
Edimax EW-7438RPn formWlanMP (ATE/MP test function) = disabled - Compensating control
Block or restrict access to the device management interfaces and the /goform/formWlanMP endpoint from untrusted networks. Implement firewall/ACL/WAF rules to allow only trusted IPs/subnets, and disable remote management where possible.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9425?
The severity of CVE-2026-9425 is high with a score of 8.8.
How do I fix CVE-2026-9425?
To fix CVE-2026-9425, update the firmware of Edimax EW-7438RPn to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-9425?
CVE-2026-9425 is a buffer overflow vulnerability affecting the Edimax EW-7438RPn.
Which function is affected by CVE-2026-9425?
The function affected by CVE-2026-9425 is formWlanMP.
What are the potential impacts of exploiting CVE-2026-9425?
Exploiting CVE-2026-9425 may lead to unauthorized access and control over the Edimax EW-7438RPn device.