Impact
The vulnerability is located in the formSDHCP function of the Edimax EW-7438RPn firmware 1.31 and arises from an unchecked submit-url argument that overflows a stack buffer. This stack-based overflow is a classic memory corruption flaw that can lead to arbitrary code execution or device termination, and it is classified under CWE-119 and CWE-121. The impact is therefore the potential loss of confidentiality, integrity, and availability of the device if an attacker successfully controls the execution flow.
Affected Systems
Only the Edimax EW-7438RPn router is listed by the CNA as affected, and the known vulnerable firmware is version 1.31; no other product or version information is provided.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity and the exploit is publicly disclosed, making the threat real for exposed devices. EPSS is not available, but the fact that the attack can be launched remotely via the web interface suggests that common attackers could reach the target. Based on the description, it is inferred that the exploit endpoint is accessed through the router’s web interface at /goform/formSDHCP, allowing attackers to send crafted requests from outside the local network. The vulnerability is not listed in the CISA KEV catalog, but the existence of a public exploit means that mitigation should be applied without delay.
OpenCVE Enrichment