Impact
A buffer overflow exists in the formWizSurvey handler of the Edimax EW-7438RPn router, triggered when an attacker manipulates ssid/manualssid/ip/mask/gateway parameters. The flaw allows remote exploitation and could lead to code execution on the device, exposing confidentiality, integrity, and availability. The vulnerability is categorized as CWE‑119 and CWE‑120 and is evaluated with a CVSS score of 8.7.
Affected Systems
The flaw affects Edimax EW‑7438RPn routers running firmware versions up to 1.31. The router’s web interface component "webs" exposes the vulnerable endpoint /goform/formWizSurvey.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, and the lack of an EPSS value means current exploitation probability is unknown, though a public exploit is available. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the vulnerable interface remotely, and the flaw can be exploited by sending crafted requests to the device’s web form.
OpenCVE Enrichment