Impact
An unexpected buffer overflow occurs when a crafted selSSID input exceeds the allocated memory area in the formWlSiteSurvey routine of the router’s web interface. The overflow can corrupt stack data and ultimately enable an attacker to run arbitrary code on the device, giving full control over the router’s operating system. This flaw belongs to unsafe buffer handling weaknesses that are typical of classic overrun bugs.
Affected Systems
The defect is confined to the Edimax EW‑7478APC router equipped with firmware release 1.04. No other variants or firmware revisions have been confirmed to be vulnerable at this time.
Risk and Exploitability
The flaw carries a CVSS rating of 9.4, classifying it as a critical vulnerability. Although no publicly available exploitation likelihood metric is supplied, the fact that a working exploit is on the internet and that the attacker can invoke the vulnerability from any network connection elevates the risk considerably. The router is not listed in the catalog of known exploited vulnerabilities, but the exposed web entry point at /goform/formWlSiteSurvey can be reached remotely without authentication, which means the attacker does not need an internal foothold to trigger the overflow.
OpenCVE Enrichment