HIGH
Edimax BR-6478AC POST Request formQoS buffer overflow
Published May 30, 2026
8.7
HIGHCVSS 4.0
EPSS 0.75%
Description
A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID results in buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected products
-
Affected
- 1.23
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33469 Advisory
- https://lavender-bicycle-a5a.notion.site/EDIMAX-BR6478ACV2-formQoS-34b53a41781f804e9ddfe771c426d9b2?source=copy_link exploit
- https://vuldb.com/submit/818454 third-party-advisory
- https://vuldb.com/vuln/367303 vdb-entrytechnical-description
- https://vuldb.com/vuln/367303/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33469 | Advisory | |
| https://lavender-bicycle-a5a.notion.site/EDIMAX-BR6478ACV2-formQoS-34b53a41781f804e9ddfe771c426d9b2?source=copy_link | exploit | |
| https://vuldb.com/submit/818454 | third-party-advisory | |
| https://vuldb.com/vuln/367303 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/367303/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published May 30, 2026
Updated Jun 1, 2026
Reserved May 29, 2026
Link CVE-2026-10126
CISA Vulnrichment
Updated Jun 1, 2026
Red Hat
No data
GitHub
No data