Impact
A buffer overflow exists in the formUSBAccount function within the POST Request Handler of the Edimax EW-7478APC. The vulnerability is triggered by manipulating the UserName and Password fields in a POST request to the /goform/formUSBAccount endpoint. The CVE notes that the overflow can be exploited remotely, and that an exploit has been published; from the nature of the overflow it is inferred that the flaw could lead to arbitrary code execution on the device if an attacker successfully controls the overflowed data.
Affected Systems
The flaw affects only the Edimax EW-7478APC appliance running firmware version 1.04. No other firmware revisions are mentioned in the advisory, so the impact is confined to this specific build.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. EPSS data are not available, but the existence of a published exploit demonstrates that the vulnerability is actionable. The device is remotely reachable, allowing an attacker to send crafted POST requests over the network. The vendor has not released a fix and the issue is not listed in CISA's KEV catalog, so exposed devices remain at elevated risk until a patch or mitigation is applied.
OpenCVE Enrichment