Impact
A stack‑based buffer overflow exists in the formL2TPSetup endpoint of the Edimax EW‑7478APC, caused by an supplied via an HTTP POST request; an attacker can craft a malicious payload that overwrites the return address on the stack and potentially execute arbitrary code, providing full control of the device.
Affected Systems
The vulnerability affects Edimax EW‑7478APC model 1.04. No other versions or products are listed as impacted, so the risk is confined to installations running this firmware revision.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity issue, and the vulnerability is remotely exploitable over the network without authentication. The EPSS score is not available, and the flaw is not currently listed in CISA KEV. Attackers can trigger the overflow by sending a specially crafted POST request to /goform/formL2TPSetup, which may lead to remote code execution on the affected device.
OpenCVE Enrichment