Impact
The vulnerability is a stack-based buffer overflow in the Wireless Wizard Handler of Edimax BR-6428nC firmware 1.16. Manipulating the interface1 and interface2 arguments in /goform/formWizSurvey can overflow a controlled buffer, potentially allowing an attacker to execute arbitrary code on the device. This flaw is classified by CWE-119 and CWE-121 and results in remote code execution.
Affected Systems
This issue affects Edimax BR-6428nC wireless routers running firmware version 1.16 released with the Wireless Wizard Handler component. The affected element is the /goform/formWizSurvey endpoint, which is normally accessed as part of the router's web-based configuration interface.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity; however, the lack of an EPSS score and absence from KEV suggest limited evidence of active exploitation. Nevertheless, the flaw is publicly disclosed and a remote attacker can trigger it over the network by sending crafted HTTP requests to the vulnerable endpoint. The earliest publicly available exploit code demonstrates that exploitation is feasible without authentication, therefore all devices exhibiting this firmware version are at risk if the management interface is reachable from untrusted networks.
OpenCVE Enrichment