Edimax EW-7438RPn
- 1.31
A stack-based buffer overflow vulnerability has been identified in the Edimax EW-7438RPn range extender, specifically in version 1.31. The issue arises in the 'formConnectionSetting' function within the 'webs' binary, where the 'max_Conn' and 'timeOut' parameters are not properly validated. This lack of input sanitization allows remote attackers to manipulate these arguments, leading to a buffer overflow that can be exploited to execute arbitrary code. The vulnerability has been publicly disclosed and could be used in attacks.
Exploitation of this vulnerability causes the device to crash, disrupting its normal functioning and service availability.
The vulnerability can be reproduced by sending a POST request to '/goform/formConnectionSetting' with overly long 'max_Conn' and 'timeOut' parameters. The excessive length of the 'max_Conn' input, for example, can overwrite the return address on the stack, causing a buffer overflow.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.