CVE-2026-9463: Edimax EW-7438RPn formLicence stack-based overflow
A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the function formLicence of the file /goform/formLicence. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Block access to the vulnerable endpoint (/goform/formLicence) at the network edge (firewall, router, or WAF). Restrict management/administration interfaces to trusted IPs only and disable remote administration if the device supports that.
- Compensating control
Deploy intrusion prevention / WAF rules to detect and block exploit attempts targeting the formLicence function and the submit-url parameter (signatures or request filtering for attempts to overflow submit-url).
- Operational
Monitor affected devices for signs of exploitation and for published indicators of compromise. Apply a vendor-supplied firmware/security update if and when the vendor releases a patch or fixed firmware; until then treat the device as untrusted and isolate or remove it from sensitive networks if exploitation is suspected.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9463?
The severity of CVE-2026-9463 is rated as high with a score of 8.8.
What does CVE-2026-9463 affect?
CVE-2026-9463 affects the Edimax EW-7438RPn version 1.31 due to a vulnerability in the function formLicence.
How can CVE-2026-9463 be exploited?
CVE-2026-9463 can be exploited remotely through a stack-based buffer overflow in the submit-url argument.
What is the impact of CVE-2026-9463?
The impact of CVE-2026-9463 could lead to compromised confidentiality, integrity, and availability of the affected system.
How can I mitigate the risk of CVE-2026-9463?
Mitigation for CVE-2026-9463 includes applying any available firmware updates or patches provided by Edimax.