CVE-2026-19961: Buffer Overflow in Edimax EW-7478APC
CVE-2026-19961 is a critical buffer overflow vulnerability in the Edimax EW-7478APC wireless access point firmware version 1.04. The flaw exists in the formWlSiteSurvey function, where manipulation of the selSSID argument can cause a buffer overflow. This vulnerability can be exploited remotely without user interaction. The vendor has not responded to disclosure requests, and no official patch or remediation guidance is currently available. Exploit code is publicly available, increasing the risk of exploitation.
AI Analysis
Technical Summary
The Edimax EW-7478APC device running firmware version 1.04 contains a buffer overflow vulnerability in the formWlSiteSurvey function located in /goform/formWlSiteSurvey. An attacker can remotely manipulate the selSSID parameter to trigger a buffer overflow condition. This vulnerability has a CVSS 4.0 score of 9.4, indicating critical severity with network attack vector, low attack complexity, no privileges required, and no user interaction needed. The vulnerability impacts confidentiality, integrity, availability, and security requirements with high impact. The vendor has not issued any patch or official remediation, and exploit code is publicly available.
Potential Impact
Successful exploitation of this vulnerability can lead to remote code execution or denial of service on the affected device. Given the critical CVSS score and the remote attack vector, attackers can potentially take full control of the device or disrupt its operation. The vulnerability affects confidentiality, integrity, and availability of the device and its network environment.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor. Users should consider isolating the affected device from untrusted networks and monitor for suspicious activity. Due to the public availability of exploit code, caution is advised until a vendor fix is released. Check the vendor's website or security advisories regularly for updates.
CVE-2026-19961: Buffer Overflow in Edimax EW-7478APC
Description
CVE-2026-19961 is a critical buffer overflow vulnerability in the Edimax EW-7478APC wireless access point firmware version 1.04. The flaw exists in the formWlSiteSurvey function, where manipulation of the selSSID argument can cause a buffer overflow. This vulnerability can be exploited remotely without user interaction. The vendor has not responded to disclosure requests, and no official patch or remediation guidance is currently available. Exploit code is publicly available, increasing the risk of exploitation.
CVSS v4.0
Score 9.4critical
Affected software
Edimax
EW-7478APC
cpe:2.3:a:edimax:ew-7478apc:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Edimax EW-7478APC device running firmware version 1.04 contains a buffer overflow vulnerability in the formWlSiteSurvey function located in /goform/formWlSiteSurvey. An attacker can remotely manipulate the selSSID parameter to trigger a buffer overflow condition. This vulnerability has a CVSS 4.0 score of 9.4, indicating critical severity with network attack vector, low attack complexity, no privileges required, and no user interaction needed. The vulnerability impacts confidentiality, integrity, availability, and security requirements with high impact. The vendor has not issued any patch or official remediation, and exploit code is publicly available.
Potential Impact
Successful exploitation of this vulnerability can lead to remote code execution or denial of service on the affected device. Given the critical CVSS score and the remote attack vector, attackers can potentially take full control of the device or disrupt its operation. The vulnerability affects confidentiality, integrity, and availability of the device and its network environment.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor. Users should consider isolating the affected device from untrusted networks and monitor for suspicious activity. Due to the public availability of exploit code, caution is advised until a vendor fix is released. Check the vendor's website or security advisories regularly for updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-16T07:07:45.859Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8243b3bf8831d539c58f31
Added to database: 08/16/2026, 23:11:47 UTC
Last enriched: 08/24/2026, 13:25:41 UTC
Last updated: 10/01/2026, 05:08:50 UTC
Views: 139
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.