A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such manipulation of the argument L2TPUserName leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Mon, 29 Jun 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such manipulation of the argument L2TPUserName leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Edimax EW-7478APC POST Request formL2TPSetup stack-based overflow | |
| First Time appeared |
Edimax
Edimax ew-7478apc |
|
| Weaknesses | CWE-119 CWE-121 |
|
| CPEs | cpe:2.3:a:edimax:ew-7478apc:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Edimax
Edimax ew-7478apc |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-06-29T11:30:08.061Z
Updated: 2026-06-29T11:30:08.061Z
Reserved: 2026-06-28T16:12:55.531Z
Link: CVE-2026-13563
No data.
No data.
No data.