PT-2026-6590 · Edimax · Edimax Ew-7438Rpn-V3 Mini

Wadeek

·

Published

2026-02-05

·

Updated

2026-02-05

·

CVE-2020-37150

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Edimax EW-7438RPn-v3 Mini version 1.27
Description The Edimax EW-7438RPn-v3 Mini version 1.27 allows unauthenticated attackers to access the /wizard reboot.asp API endpoint in unsetup mode. This access discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without authentication.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2020-37150

Affected Products

Edimax Ew-7438Rpn-V3 Mini