Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119)
A buffer overflow vulnerability exists in the formWlSiteSurvey function of the /goform/formWlSiteSurvey POST request handler in Edimax BR-6478AC V2 1.23. The vulnerability is triggered through manipulation of the selSSID argument, which does not properly validate input length before copying data to a fixed-size buffer.
An authenticated user with low privileges can trigger this vulnerability remotely over the network and execute arbitrary code on the device with the privileges of the affected service.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
No patch information available. The vendor was contacted early this disclosure but did not respond.
Implement network segmentation to restrict access to the device's management interface. Disable remote administration if not required. Monitor for exploitation attempts targeting the /goform/formWlSiteSurvey endpoint. Consider replacing the device with a model from a vendor that provides timely security updates. If the device must remain in use, apply strict authentication controls and limit access to trusted networks only.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Feedly found the first article mentioning CVE-2026-12806 . See article
NVD published the first details for CVE-2026-12806
A CVSS base score of 8.8 has been assigned.
GitHub Advisories released a security advisory .
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
