CVE-2026-9461: Edimax EW-7438RPn formRadius stack-based overflow

Published May 25, 2026
·
Updated

A security vulnerability has been detected in Edimax EW-7438RPn 1.31. Affected is the function formRadius of the file /goform/formRadius. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

1 affected component
Edimax EW-7438RPn=1.31

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Block or restrict remote access to the device management interface from untrusted networks. Implement firewall/ACL rules to prevent WAN/internet access to the device's administration ports.

  2. Compensating control

    Use a WAF/NGFW or perimeter filtering to block HTTP(S) requests to the vulnerable endpoint path /goform/formRadius (deny POST/PUT requests to that URI) until a vendor fix is available.

  3. Compensating control

    Isolate affected devices from untrusted networks (place them on a management VLAN with no internet access) or disconnect them from the internet until a vendor-provided patch or mitigation is available.

  4. Operational

    Inspect device and network logs for signs of exploitation (requests to /goform/formRadius, unexpected reboots, configuration changes). If compromise is suspected, remove the device from network, perform a factory reset or replace the device, and rotate any credentials that may have been used to manage it.

  5. Operational

    Monitor the vendor's advisories and security channels for an official patch or firmware update and apply the vendor-supplied fix as soon as it becomes available.

Event History

May 25, 2026
CVE Published
via MITRE·01:15 PM
Data Sourced
via MITRE·01:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Jun 29, 58424
Event
via FIRST·02:56 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-9461?

CVE-2026-9461 has a high severity score of 8.8.

2

What type of vulnerability is identified in CVE-2026-9461?

CVE-2026-9461 is a stack-based buffer overflow vulnerability.

3

How can CVE-2026-9461 be exploited?

CVE-2026-9461 can be exploited remotely through the manipulation of the submit-url argument.

4

What is the affected software version for CVE-2026-9461?

CVE-2026-9461 affects Edimax EW-7438RPn version 1.31.

5

How do I fix CVE-2026-9461?

To fix CVE-2026-9461, update your Edimax EW-7438RPn to a patched version provided by the manufacturer.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203