Edimax EW-7438RPn Stack-Based Buffer Overflow Vulnerability in WPS Proxy Enable Function

Vulnerability

A stack-based buffer overflow vulnerability has been identified in the Edimax EW-7438RPn range extender, specifically in version 1.31. The issue arises in the 'formWpsProxyEnable' function, where the 'submit-url' parameter is not properly validated before being processed. This oversight allows remote attackers to manipulate the input, leading to a buffer overflow by overwriting the function's return address. The exploitation of this vulnerability causes the device to crash and fail to provide services correctly.

Impact

Exploitation of this vulnerability leads to a stack-based buffer overflow, allowing for arbitrary code execution. However, in this case, the vulnerability causes the device to crash and disrupt normal services.

Reproduction

To reproduce this vulnerability, send a POST request to '/goform/formWpsProxyEnable' with a 'wlan-url' parameter containing a long string. The excessive length will cause a stack overflow, overwriting the return address and crashing the router.

Added: May 26, 2026, 7:13 PM
Updated: May 26, 2026, 7:13 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.2
remediation
0.0
relevance
9.4
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.