CVE-2026-9461: Edimax EW-7438RPn formRadius stack-based overflow
A security vulnerability has been detected in Edimax EW-7438RPn 1.31. Affected is the function formRadius of the file /goform/formRadius. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Block or restrict remote access to the device management interface from untrusted networks. Implement firewall/ACL rules to prevent WAN/internet access to the device's administration ports.
- Compensating control
Use a WAF/NGFW or perimeter filtering to block HTTP(S) requests to the vulnerable endpoint path /goform/formRadius (deny POST/PUT requests to that URI) until a vendor fix is available.
- Compensating control
Isolate affected devices from untrusted networks (place them on a management VLAN with no internet access) or disconnect them from the internet until a vendor-provided patch or mitigation is available.
- Operational
Inspect device and network logs for signs of exploitation (requests to /goform/formRadius, unexpected reboots, configuration changes). If compromise is suspected, remove the device from network, perform a factory reset or replace the device, and rotate any credentials that may have been used to manage it.
- Operational
Monitor the vendor's advisories and security channels for an official patch or firmware update and apply the vendor-supplied fix as soon as it becomes available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9461?
CVE-2026-9461 has a high severity score of 8.8.
What type of vulnerability is identified in CVE-2026-9461?
CVE-2026-9461 is a stack-based buffer overflow vulnerability.
How can CVE-2026-9461 be exploited?
CVE-2026-9461 can be exploited remotely through the manipulation of the submit-url argument.
What is the affected software version for CVE-2026-9461?
CVE-2026-9461 affects Edimax EW-7438RPn version 1.31.
How do I fix CVE-2026-9461?
To fix CVE-2026-9461, update your Edimax EW-7438RPn to a patched version provided by the manufacturer.