Sceawere
Vulnerability Detail
CVE-2026-100745UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Edimax BR-6428nC Buffer Overflow
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 1d ago
- Vendor
- Edimax
- Product
- BR-6428nC
- Attack Type
- Stack-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability has been found in Edimax BR-6428nC 1.16. The impacted element is an unknown function of the file /goform/formWizSurvey of the component Wireless Wizard Handler. The manipulation of the argument interface1/interface2 leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-09-27T02:17:21.123Z",
"pubdate": "2026-09-27T02:17:21.123Z",
"executiveSummary": "A critical stack-based buffer overflow vulnerability exists in the Edimax BR-6428nC firmware version 1.16, specifically within the Wireless Wizard Handler component.\nThe vulnerability resides in the /goform/formWizSurvey script, which improperly handles input provided via the interface1 or interface2 arguments.\nThis security flaw allows remote, unauthenticated attackers to trigger a buffer overflow by supplying malicious input to the susceptible form handler.\nSuccessful exploitation may lead to arbitrary code execution, system instability, or a complete denial-of-service condition on the affected networking device.\nGiven that the exploit has been disclosed publicly, the risk of exploitation by malicious actors is elevated, necessitating immediate defensive measures to secure the perimeter.",
"technicalDetails": "The vulnerability originates from a stack-based buffer overflow within the Wireless Wizard Handler of the Edimax BR-6428nC, version 1.16 firmware. The flaw is localized to the /goform/formWizSurvey endpoint, which acts as a gateway for processing survey-related wireless configurations.\nThe root cause is identified as an unsafe handling of the interface1 and interface2 HTTP POST/GET parameters. The underlying function responsible for processing these inputs fails to perform adequate bounds checking on the user-supplied data before copying it into a fixed-size stack buffer. This allows an attacker to provide an input string of excessive length, which overflows the allocated buffer memory.\nExploitation is achieved by sending a crafted HTTP request to the vulnerable endpoint. By injecting a payload designed to overwrite the stack, an attacker can manipulate the instruction pointer (such as the return address) to redirect the execution flow. This control allows the execution of arbitrary shellcode injected within the payload, potentially granting the attacker remote command execution privileges on the underlying operating system.\nThe attack flow follows these stages: First, the attacker identifies the /goform/formWizSurvey URI as a target for interaction with the device's wireless wizard interface. Second, the attacker crafts a malicious request where the interface1 or interface2 parameters contain a specific sequence of bytes exceeding the expected buffer size, typically including NOP slides and a malicious payload. Third, the application's internal handler process copies this input into memory without verification, leading to the corruption of adjacent memory structures, including the function's return pointer. Finally, upon the completion of the function call, the device attempts to return to the overwritten address, effectively executing the attacker's supplied code.\nThis vulnerability is particularly severe as it is remotely exploitable without requiring prior authentication. The impact includes full compromise of the device firmware, persistent access, or potential lateral movement within the network. Because the exploit vector is publicly documented, the barrier to entry for exploitation is low, necessitating strict access control to the administrative interface of the device."
}