Skip to content
Critical Buffer Overflow Vulnerability in Edimax BR-6478AC V2 Disclosed

Critical Buffer Overflow Vulnerability in Edimax BR-6478AC V2 Disclosed

First seen 22 Jun 2026, 00:03 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 22, 2026 at 23:40 UTC
  • CVE-2026-12806 is a critical buffer overflow vulnerability in Edimax BR-6478AC V2.
  • The vulnerability allows remote code execution by authenticated users with low privileges.
  • No patches are available, and the vendor has not responded to disclosure attempts.

A buffer overflow vulnerability, CVE-2026-12806, has been identified in the Edimax BR-6478AC V2 1.23 router. This flaw exists in the formWlSiteSurvey function, where the selSSID argument is not properly validated, allowing authenticated users with low privileges to execute arbitrary code remotely. The vulnerability has a CVSS score of 8.8, indicating a high severity level. Currently, there is no evidence of public exploitation or proof-of-concept code. The vendor has not responded to disclosure attempts, and no patches are available. Security experts recommend network segmentation and strict access controls as mitigations. The vulnerability was published on June 21, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2026-06-21
CVE-2026-12806 published
The vulnerability in Edimax BR-6478AC V2 was disclosed, allowing remote exploitation via a buffer overflow.
Feedly
2026-06-21
NVD entry created for CVE-2026-12806
The National Vulnerability Database published details on the buffer overflow vulnerability affecting Edimax devices.
nvd.nist.gov
2026-06-21
AKAOMA CVE entry published
AKAOMA CVE database reported the same vulnerability, emphasizing its severity and need for urgent mitigation.
cve.akaoma.com

More articles in this cluster (9)

Following this threat?

Track CVE-2026-12806 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed