Vulnerability Description
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://lavender-bicycle-a5a.notion.site/EDIMAX-EW-7478APC-formWlSiteSurvey-34b5
- https://vuldb.com/cve/CVE-2026-19961
- https://vuldb.com/submit/872875
- https://vuldb.com/vuln/391138
- https://vuldb.com/vuln/391138/cti
FAQ
What is CVE-2026-19961?
CVE-2026-19961 is a vulnerability with a CVSS score of 9.9 (CRITICAL). A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buf...
How severe is CVE-2026-19961?
CVE-2026-19961 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-19961?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.