CVE-2026-9459: Edimax EW-7438RPn formConnectionSetting stack-based overflow
A security flaw has been discovered in Edimax EW-7438RPn 1.31. This affects the function formConnectionSetting of the file /goform/formConnectionSetting. Performing a manipulation of the argument max_Conn/timeOut results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9459?
The severity of CVE-2026-9459 is rated high with a score of 8.8.
What causes CVE-2026-9459?
CVE-2026-9459 is caused by a stack-based buffer overflow in the formConnectionSetting function due to the manipulation of the max_Conn/timeOut arguments.
How can I fix CVE-2026-9459?
To fix CVE-2026-9459, update your Edimax EW-7438RPn device to the latest firmware version that addresses this vulnerability.
Is CVE-2026-9459 remotely exploitable?
Yes, CVE-2026-9459 can be exploited remotely, which increases the risk associated with this vulnerability.
What impact does CVE-2026-9459 have on systems?
CVE-2026-9459 can lead to remote code execution due to the buffer overflow, potentially allowing an attacker to gain unauthorized access.