Description
A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the function formLicence of the file /goform/formLicence. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-05-25
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack‑based buffer overflow exists in the formLicence function of Edimax EW‑7438RPn firmware 1.31, triggered by manipulating the submit‑url argument. The overflow can overwrite control data on the stack, enabling the attacker to execute arbitrary code with the privileges of the web service. This gives the attacker full control over the device, exposing it to complete compromise.

Affected Systems

The vulnerability affects the Edimax EW‑7438RPn router running firmware version 1.31. No other versions or manufacturers are listed. Users of this hardware should verify their firmware version and update if necessary.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability, and the exploit has already been published and is known to be usable. No EPSS value is available and the issue is not listed in the CISA KEV catalog, but the remote attack vector and lack of immediate patch response increase the risk. This combination suggests a moderate to high likelihood of exploitation by adversaries with sufficient motivation.

Generated by OpenCVE AI on May 25, 2026 at 15:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest official version that resolves the formLicence buffer overflow. If a patch is not yet published, check the vendor’s website for any interim fixes or advisories.
  • Block remote HTTP access to the /goform/formLicence endpoint by configuring firewall rules or disabling remote management in the router’s settings to prevent the overflow from being triggered over the network.
  • Monitor device logs and network traffic for anomalous POST requests to /goform/formLicence and for signs of arbitrary code execution, and apply intrusion detection rules if available.

Generated by OpenCVE AI on May 25, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 25 May 2026 14:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the function formLicence of the file /goform/formLicence. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Edimax EW-7438RPn formLicence stack-based overflow
First Time appeared Edimax
Edimax ew-7438rpn
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:edimax:ew-7438rpn:*:*:*:*:*:*:*:*
Vendors & Products Edimax
Edimax ew-7438rpn
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Edimax Ew-7438rpn
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-26T14:57:22.802Z

Reserved: 2026-05-24T08:03:14.471Z

Link: CVE-2026-9463

cve-icon Vulnrichment

Updated: 2026-05-26T14:57:18.675Z

cve-icon NVD

Status : Deferred

Published: 2026-05-25T15:16:23.233

Modified: 2026-05-26T19:54:40.357

Link: CVE-2026-9463

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T16:45:26Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow