CVE-2020-37149: Edimax Technology EW-7438RPn-v3 Mini 1.27 - Cross-Site Request Forgery (CSRF) to Command Execution
Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An attacker can trick an authenticated user into submitting a crafted form to the /goform/mp endpoint, resulting in arbitrary command execution on the device with the user's privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37149?
CVE-2020-37149 is classified as a high severity vulnerability due to its potential for command execution via CSRF.
How do I fix CVE-2020-37149?
To fix CVE-2020-37149, update the Edimax EW-7438RPn-v3 Mini to the latest firmware version that addresses this vulnerability.
What impact does CVE-2020-37149 have on my device?
CVE-2020-37149 allows an attacker to execute commands on the Edimax EW-7438RPn-v3 Mini by tricking an authenticated user into performing malicious actions.
Who is affected by CVE-2020-37149?
Users of the Edimax EW-7438RPn-v3 Mini running version 1.27 are directly affected by CVE-2020-37149.
Is there a workaround for CVE-2020-37149?
Avoid using the vulnerable version and consider implementing CSRF protections as a temporary measure until firmware updates are available.