SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-19961 2026-08-16

Edimax EW-7478APC Buffer Overflow (CVE-2026-19961) — Public Exploit, No Vendor Response

"A remotely reachable buffer overflow in the Edimax EW-7478APC access point carries a CVSS 3.1 score of 9.9 (Critical), has a public exploit, and the vendor did not respond to disclosure attempts."

A remotely reachable buffer overflow in the Edimax EW-7478APC access point carries a CVSS 3.1 score of 9.9 (Critical), has a public exploit, and the vendor did not respond to disclosure attempts.

What Is It

CVE-2026-19961 is a buffer overflow in the formWlSiteSurvey function of /goform/formWlSiteSurvey on the Edimax EW-7478APC. Manipulating the selSSID argument triggers the overflow. The issue is classified under CWE-119 (improper restriction of operations within the bounds of a memory buffer) and CWE-120 (classic buffer overflow), and was assigned by VulDB as the CNA.

The attack can be carried out remotely. The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network reachable, low complexity, no user interaction, and requiring only low privileges. The scope is marked Changed, meaning impact extends beyond the vulnerable component, which is what pushes the score to 9.9. A CVSS 4.0 secondary score of 8.6 (High) and a CVSS 2.0 score of 9.0 are also assigned.

Why It Matters

The exploit is public and may be used. The CVSS 4.0 exploit maturity is rated Proof-of-Concept, and a write-up of the flaw is published externally. Confidentiality, integrity, and availability impacts are all High for both the vulnerable component and downstream subsystems.

Critically, the researcher contacted the vendor early about this disclosure and received no response of any kind. That leaves affected operators with a publicly documented, remotely triggerable memory corruption bug and no vendor engagement.

This CVE does not appear in the CISA Known Exploited Vulnerabilities catalog in the supplied data; no KEV entry, no confirmed in-the-wild exploitation, and no federal remediation deadline.

What's Vulnerable

Only version 1.04 is listed as affected in the NVD record.

Patch Status

No patch, fix, or vendor advisory is referenced in the supplied data. The vendor did not respond to the disclosure. The NVD record status is "Received," published 2026-08-16, and no required-action or remediation guidance is provided.

Sources