


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was identified in Edimax BR-6478AC 1.23. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the com…
Published:
30 May 2026 at 22:00:00
Alert date:
31 May 2026 at 05:01:06
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A critical stack-based buffer overflow vulnerability has been identified in Edimax BR-6478AC firmware version 1.23. The vulnerability exists in the formWanTcpipSetup function of the POST Request Handler component, specifically in the /goform/formWanTcpipSetup file. The flaw can be exploited by manipulating the pppUserName argument, leading to a stack-based buffer overflow condition. This vulnerability can be exploited remotely by attackers without requiring authentication. Public exploits are already available, making this a high-priority security concern for organizations using affected devices. The vulnerability poses significant risk as it affects network infrastructure equipment and can be exploited from remote locations.
Technical details
Mitigation steps:
Affected products:
Edimax BR-6478AC
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10165
https://lavender-bicycle-a5a.notion.site/EDIMAX-BR6478ACV2-formWanTcpipSetup-34b53a41781f8013a811da2b3c8b7aa3?source=copy_link
https://vuldb.com/submit/818601
https://vuldb.com/vuln/367419
https://vuldb.com/vuln/367419/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
