Edimax Ew 7478apc
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Edimax Ew 7478apc.
By the Year
In 2026 there have been 14 vulnerabilities in Edimax Ew 7478apc with an average score of 7.6 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 14 | 7.60 |
It may take a day or so for new Ew 7478apc vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Edimax Ew 7478apc Security Vulnerabilities
Edimax EW-7478APC 1.04 Remote cmd injection via /goform/stainfo
CVE-2026-19963
5.3 - Medium
- August 16, 2026
A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function stainfo of the file /goform/stainfo. The manipulation of the argument interface leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Command Injection
Command Injection via setWAN in Edimax EW-7478APC 1.04 (pppUserName/v1.04)
CVE-2026-19962
5.3 - Medium
- August 16, 2026
A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipulation of the argument pppUserName/pptpUserName/L2TPUserName can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Command Injection
Edimax EW-7478APC 1.04 Buffer Overflow in formWlSiteSurvey (Remote)
CVE-2026-19961
9.4 - Critical
- August 16, 2026
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Classic Buffer Overflow
Command Injection in Edimax EW-7478APC 1.04, formWlbasic rootAPmac exploit
CVE-2026-19960
5.3 - Medium
- August 16, 2026
A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such manipulation of the argument rootAPmac leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Command Injection
Edimax EW-7478APC 1.04 Remote Stack Buffer Overflow via pppUserName
CVE-2026-19959
9.4 - Critical
- August 16, 2026
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Stack Overflow
Edimax EW-7478APC 1.04 Buffer Overflow via /goform/formUSBFolder POST
CVE-2026-13583
8.8 - High
- June 29, 2026
A vulnerability has been found in Edimax EW-7478APC 1.04. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. Such manipulation of the argument ShareName/SelectName leads to buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Classic Buffer Overflow
Edimax EW-7478APC 1.04 Buffer Overflow via formUSBAccount (POST Handler)
CVE-2026-13582
8.8 - High
- June 29, 2026
A flaw has been found in Edimax EW-7478APC 1.04. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. This manipulation of the argument UserName/Password causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Classic Buffer Overflow
Edimax EW-7478APC 1.04 - OS-Command Injection via rootAPmac POST
CVE-2026-13581
6.3 - Medium
- June 29, 2026
A vulnerability was detected in Edimax EW-7478APC 1.04. This vulnerability affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. The manipulation of the argument rootAPmac results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Shell injection
Buffer Overflow in Edimax EW-7478APC 1.04 /goform/formQoS (POST)
CVE-2026-13580
8.8 - High
- June 29, 2026
A security vulnerability has been detected in Edimax EW-7478APC 1.04. This affects the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Classic Buffer Overflow
Stack-based BO in Edimax EW-7478APC 1.04 POST Handler
CVE-2026-13564
8.8 - High
- June 29, 2026
A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. Performing a manipulation of the argument pppUserName results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Stack Overflow
Edimax EW-7478APC 1.04: Remote Stack BOF via L2TPUserName
CVE-2026-13563
8.8 - High
- June 29, 2026
A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such manipulation of the argument L2TPUserName leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Stack Overflow
Buffer overflow via formiNICSiteSurvey in Edimax EW-7478APC 1.04 POST
CVE-2026-13562
8.8 - High
- June 29, 2026
A flaw has been found in Edimax EW-7478APC 1.04. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. This manipulation of the argument selSSID causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Classic Buffer Overflow
Edimax EW-7478APC 1.04: POST /goform/formiNICbasic rootAPmac OS Cmd Injection
CVE-2026-13561
6.3 - Medium
- June 29, 2026
A vulnerability was detected in Edimax EW-7478APC 1.04. The impacted element is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. The manipulation of the argument rootAPmac results in os command injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Shell injection
Edimax EW-7478APC 1.04 OS Command Injection via formAccept
CVE-2026-13560
6.3 - Medium
- June 29, 2026
A security vulnerability has been detected in Edimax EW-7478APC 1.04. The affected element is the function formAccept of the file /goform/formAccept of the component POST Request Handler. The manipulation of the argument submit-url leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Shell injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Edimax Ew 7478apc or by Edimax? Click the Watch button to subscribe.