CVE-2020-37097: Edimax EW-7438RPn 1.13 - Information Disclosure (WiFi Password)
Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencryptwiz.asp file. Attackers can access the script to retrieve sensitive information including WiFi network name and plaintext password stored in device configuration variables.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37097?
CVE-2020-37097 has a severity rating that indicates it poses a moderate risk of information disclosure.
How do I fix CVE-2020-37097?
To mitigate CVE-2020-37097, users should update the Edimax EW-7438RPn firmware to the latest version provided by the manufacturer.
What information is exposed by CVE-2020-37097?
CVE-2020-37097 exposes sensitive WiFi network configuration details, including the WiFi password.
Who is affected by CVE-2020-37097?
CVE-2020-37097 affects users of the Edimax EW-7438RPn with firmware version 1.13.
Can CVE-2020-37097 be exploited remotely?
Yes, CVE-2020-37097 can be exploited remotely if the wlencrypt_wiz.asp file is accessible to an attacker.