Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-19961: Edimax EW-7478APC allows remote data overflow attacks

CVE-2026-19961 · published 18 days ago
Summary

A security flaw in Edimax EW-7478APC's software allows hackers to send malicious data that can cause the system to behave unexpectedly. This can happen remotely, which means it's a risk for anyone using this device. The vendor has not responded to the issue, so users should consider updating the software or replacing the device if possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
edimax ew-7478apc 1.04
Original advisory text
Edimax EW-7478APC formWlSiteSurvey buffer overflow
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity
8.6 High
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-120Classic Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published16 Aug 2026
Updated3 Sep 2026
First seen16 Aug 2026
Sources
CVE-2026-19961 · MITRE
Monitor software like this
Free during beta