Impact
A stack‑based buffer overflow exists in the formLicence function of Edimax EW‑7438RPn firmware 1.31, triggered by manipulating the submit‑url argument. The overflow can overwrite control data on the stack, enabling the attacker to execute arbitrary code with the privileges of the web service. This gives the attacker full control over the device, exposing it to complete compromise.
Affected Systems
The vulnerability affects the Edimax EW‑7438RPn router running firmware version 1.31. No other versions or manufacturers are listed. Users of this hardware should verify their firmware version and update if necessary.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability, and the exploit has already been published and is known to be usable. No EPSS value is available and the issue is not listed in the CISA KEV catalog, but the remote attack vector and lack of immediate patch response increase the risk. This combination suggests a moderate to high likelihood of exploitation by adversaries with sufficient motivation.
OpenCVE Enrichment