Impact
The vulnerability is a stack‑based buffer overflow located in the formWlanMP function of the /goform/formWlanMP endpoint. The function accepts a long list of parameters such as ateFunc, ateGain, and multiple e2pTxPower values, which can be manipulated to overflow a local buffer. This overflow can allow an attacker to execute arbitrary code or crash the device, providing remote compromise or denial of service. The weakness aligns with CWE‑119 and CWE‑121.
Affected Systems
Edimax EW‑7438RPn, firmware version 1.31, accessed via the device’s web interface.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the exploit is remotely exploitable through crafted HTTP requests to the web interface. The EPSS score is unavailable and the vulnerability is not listed in KEV, suggesting no widespread, known active exploitation at present. The attack vector is inferred to be a remote HTTP request from an unauthenticated or authenticated attacker with network access to the device’s management interface.
OpenCVE Enrichment