PT-2026-6589 · Edimax · Edimax Ew-7438Rpn-V3 Mini

Wadeek

·

Published

2026-02-05

·

Updated

2026-02-05

·

CVE-2020-37149

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Edimax EW-7438RPn-v3 Mini version 1.27
Description The Edimax EW-7438RPn-v3 Mini device version 1.27 is susceptible to a cross-site request forgery (CSRF) issue. Successful exploitation allows an attacker to execute commands on the device with the privileges of an authenticated user. This is achieved by tricking a user into submitting a specially crafted form to the /goform/mp API endpoint.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2020-37149

Affected Products

Edimax Ew-7438Rpn-V3 Mini