Critical Buffer Overflow Vulnerability in Edimax BR-6478AC V2 Disclosed

Critical Buffer Overflow Vulnerability in Edimax BR-6478AC V2 Disclosed

First seen 22 Jun 2026, 00:03 UTC Feedlycve.akaoma.comnvd.nist.goveuvd.enisa.europa.euvulners.com+1 90% similarity 71.0

Article Content

Browse articles
ThreatCluster

A buffer overflow vulnerability, CVE-2026-12806, has been identified in the Edimax BR-6478AC V2 1.23 router. This flaw exists in the formWlSiteSurvey function, where the selSSID argument is not properly validated, allowing authenticated users with low privileges to execute arbitrary code remotely. The vulnerability has a CVSS score of 8.8, indicating a high severity level. Currently, there is no evidence of public exploitation or proof-of-concept code. The vendor has not responded to disclosure attempts, and no patches are available. Security experts recommend network segmentation and strict access controls as mitigations. The vulnerability was published on June 21, 2026.

Key Points: • CVE-2026-12806 is a critical buffer overflow vulnerability in Edimax BR-6478AC V2. • The vulnerability allows remote code execution by authenticated users with low privileges. • No patches are available, and the vendor has not responded to disclosure attempts.

ThreatCluster AI How this analysis works

Timeline

2026-06-21
CVE-2026-12806 published
The vulnerability in Edimax BR-6478AC V2 was disclosed, allowing remote exploitation via a buffer overflow.
Feedly
2026-06-21
NVD entry created for CVE-2026-12806
The National Vulnerability Database published details on the buffer overflow vulnerability affecting Edimax devices.
nvd.nist.gov
2026-06-21
AKAOMA CVE entry published
AKAOMA CVE database reported the same vulnerability, emphasizing its severity and need for urgent mitigation.
cve.akaoma.com

Community

Browse all →

Tracked Entities in This Story