CVE-2020-37125: Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution
Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection payloads to download and execute malicious scripts on the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37125?
CVE-2020-37125 is classified as a critical vulnerability due to its potential for remote code execution by unauthenticated attackers.
How do I fix CVE-2020-37125?
To fix CVE-2020-37125, update the Edimax EW-7438RPn-v3 Mini to the latest firmware version that addresses this vulnerability.
Who is affected by CVE-2020-37125?
The CVE-2020-37125 vulnerability affects users of the Edimax EW-7438RPn-v3 Mini wireless range extender.
What kind of attack can be carried out using CVE-2020-37125?
An exploit of CVE-2020-37125 allows attackers to execute arbitrary commands on the affected device through the /goform/mp endpoint.
Is CVE-2020-37125 exploitable remotely?
Yes, CVE-2020-37125 can be exploited remotely without authentication, making it particularly dangerous.