Impact
A stack-based buffer overflow exists in the formWpsProxyEnable function of Edimax EW‑7438RPn routers, caused by manipulating the submit‑url argument passed to the "/goform/formWpsProxyEnable" endpoint. The overflow enables an attacker to execute arbitrary code on the device. The vulnerability is exposed through a remote interface, meaning an external attacker can trigger it without physical access. Because the exploit code is publicly available, the potential damage includes full device compromise, persistence, and denial of service.
Affected Systems
The flaw affects Edimax EW‑7438RPn models running firmware version 1.31. No other firmware or model versions were explicitly listed as affected in the available data.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. EPSS is not available, so the current publicly known exploitation probability cannot be determined. The vulnerability is not listed in the CISA KEV catalog, but the exploit is publicly available, implying a realistic risk of exploitation. Because the attack vector is remote and no patch is reported, the risk to exposed devices remains high until mitigation measures are deployed.
OpenCVE Enrichment