CVE-2026-9463: Edimax EW-7438RPn formLicence stack-based overflow

Published May 25, 2026
·
Updated

A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the function formLicence of the file /goform/formLicence. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

1 affected component
Edimax EW-7438RPn=1.31

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Block access to the vulnerable endpoint (/goform/formLicence) at the network edge (firewall, router, or WAF). Restrict management/administration interfaces to trusted IPs only and disable remote administration if the device supports that.

  2. Compensating control

    Deploy intrusion prevention / WAF rules to detect and block exploit attempts targeting the formLicence function and the submit-url parameter (signatures or request filtering for attempts to overflow submit-url).

  3. Operational

    Monitor affected devices for signs of exploitation and for published indicators of compromise. Apply a vendor-supplied firmware/security update if and when the vendor releases a patch or fixed firmware; until then treat the device as untrusted and isolate or remove it from sensitive networks if exploitation is suspected.

Event History

May 25, 2026
CVE Published
via MITRE·01:45 PM
Data Sourced
via MITRE·01:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Apr 27, 58520
Event
via FIRST·10:48 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-9463?

The severity of CVE-2026-9463 is rated as high with a score of 8.8.

2

What does CVE-2026-9463 affect?

CVE-2026-9463 affects the Edimax EW-7438RPn version 1.31 due to a vulnerability in the function formLicence.

3

How can CVE-2026-9463 be exploited?

CVE-2026-9463 can be exploited remotely through a stack-based buffer overflow in the submit-url argument.

4

What is the impact of CVE-2026-9463?

The impact of CVE-2026-9463 could lead to compromised confidentiality, integrity, and availability of the affected system.

5

How can I mitigate the risk of CVE-2026-9463?

Mitigation for CVE-2026-9463 includes applying any available firmware updates or patches provided by Edimax.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203