Description
A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The impacted element is the function formWlanMP of the file /goform/formWlanMP. The manipulation of the argument ateFunc/ateGain/ateTxCount/ateChan/ateRate/ateMacID/e2pTxPower1/e2pTxPower2/e2pTxPower3/e2pTxPower4/e2pTxPower5/e2pTxPower6/e2pTxPower7/e2pTx2Power1/e2pTx2Power2/e2pTx2Power3/e2pTx2Power4/e2pTx2Power5/e2pTx2Power6/e2pTx2Power7/ateTxFreqOffset/ateMode/ateBW/ateAntenna/e2pTxFreqOffset/e2pTxPwDeltaB/e2pTxPwDeltaG/e2pTxPwDeltaMix/e2pTxPwDeltaN/readE2P leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Problem types
Product status
Timeline
| 2026-05-24: | Advisory disclosed |
| 2026-05-24: | VulDB entry created |
| 2026-05-24: | VulDB entry last update |
Credits
Bond_yes (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/365406 (VDB-365406 | Edimax EW-7438RPn formWlanMP stack-based overflow)
vuldb.com/vuln/365406/cti (VDB-365406 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/813892 (Submit #813892 | Edimax EW-7438RPn 1.31 Stack-based Buffer Overflow)
github.com/wudipjq/my_vuln/blob/main/Edimax/vuln_8/8.md