Edimax · Ew-7478Apc · CVE-2026-13582
**Name of the Vulnerable Software and Affected Versions**
Edimax EW-7478APC version 1.04
**Description**
A buffer overflow exists in the POST Request Handler component. The issue occurs within the `formUSBAccount()` function located in the `/goform/formUSBAccount` endpoint. A remote attacker can trigger this flaw by manipulating the `UserName` and `Password` variables. A buffer overflow is a condition where a program writes more data to a block of memory, or buffer, than it is allowed to hold, potentially leading to crashes or arbitrary code execution.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Isolate affected devices immediately.