Edimax EW-7438RPn
- 1.31
A stack-based buffer overflow vulnerability has been identified in the Edimax EW-7438RPn range extender, specifically in version 1.31. The issue arises in the 'formWpsProxyEnable' function, where the 'submit-url' parameter is not properly validated before being processed. This oversight allows remote attackers to manipulate the input, leading to a buffer overflow by overwriting the function's return address. The exploitation of this vulnerability causes the device to crash and fail to provide services correctly.
Exploitation of this vulnerability leads to a stack-based buffer overflow, allowing for arbitrary code execution. However, in this case, the vulnerability causes the device to crash and disrupt normal services.
To reproduce this vulnerability, send a POST request to '/goform/formWpsProxyEnable' with a 'wlan-url' parameter containing a long string. The excessive length will cause a stack overflow, overwriting the return address and crashing the router.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.