A remotely reachable buffer overflow in the Edimax EW-7478APC access point carries a CVSS 3.1 score of 9.9 (Critical), has a public exploit, and the vendor did not respond to disclosure attempts.
What Is It
CVE-2026-19961 is a buffer overflow in the formWlSiteSurvey function of /goform/formWlSiteSurvey on the Edimax EW-7478APC. Manipulating the selSSID argument triggers the overflow. The issue is classified under CWE-119 (improper restriction of operations within the bounds of a memory buffer) and CWE-120 (classic buffer overflow), and was assigned by VulDB as the CNA.
The attack can be carried out remotely. The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network reachable, low complexity, no user interaction, and requiring only low privileges. The scope is marked Changed, meaning impact extends beyond the vulnerable component, which is what pushes the score to 9.9. A CVSS 4.0 secondary score of 8.6 (High) and a CVSS 2.0 score of 9.0 are also assigned.
Why It Matters
The exploit is public and may be used. The CVSS 4.0 exploit maturity is rated Proof-of-Concept, and a write-up of the flaw is published externally. Confidentiality, integrity, and availability impacts are all High for both the vulnerable component and downstream subsystems.
Critically, the researcher contacted the vendor early about this disclosure and received no response of any kind. That leaves affected operators with a publicly documented, remotely triggerable memory corruption bug and no vendor engagement.
This CVE does not appear in the CISA Known Exploited Vulnerabilities catalog in the supplied data; no KEV entry, no confirmed in-the-wild exploitation, and no federal remediation deadline.
What's Vulnerable
- Vendor: Edimax
- Product: EW-7478APC
- Version: 1.04 (affected)
- CPE:
cpe:2.3:a:edimax:ew-7478apc:*:*:*:*:*:*:*:*
Only version 1.04 is listed as affected in the NVD record.
Patch Status
No patch, fix, or vendor advisory is referenced in the supplied data. The vendor did not respond to the disclosure. The NVD record status is "Received," published 2026-08-16, and no required-action or remediation guidance is provided.
Sources
- NVD, CVE-2026-19961: https://nvd.nist.gov/vuln/detail/CVE-2026-19961
- VulDB, CVE-2026-19961: https://vuldb.com/cve/CVE-2026-19961
- VulDB, Vulnerability 391138: https://vuldb.com/vuln/391138
- VulDB, CTI Data 391138: https://vuldb.com/vuln/391138/cti
- VulDB, Submission 872875: https://vuldb.com/submit/872875
- Researcher write-up (Notion): https://lavender-bicycle-a5a.notion.site/EDIMAX-EW-7478APC-formWlSiteSurvey-34b53a41781f804fb328d87416095401