216.73.216.233

CVE-2020-37150

· Published 05/02/2026 17:16 · Modified 05/02/2026 20:47

Labels: CVE-2020-37150 2026-02-05CVE-2020-37150CWE-201[email protected]

Essential information

Published
05/02/2026 17:16
Modified
05/02/2026 20:47
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without authentication.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
edimax / ew-7438rpn-v3 mini cpe:2.3:a:edimax:ew-7438rpn-v3_mini:1.27:*:*:*:*:*:*:*

References