CVE-2020-37150: Edimax Technology EW-7438RPn-v3 Mini 1.27 - Unauthorized Access: Wi-Fi Password Disclosure
Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizardreboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37150?
The severity of CVE-2020-37150 is considered to be high due to the potential for unauthorized access to sensitive Wi-Fi credentials.
How do I fix CVE-2020-37150?
To fix CVE-2020-37150, ensure that the device firmware is updated to the latest version provided by Edimax Technology.
Who is affected by CVE-2020-37150?
CVE-2020-37150 affects users of the Edimax Technology EW-7438RPn-v3 Mini running version 1.27.
What are the potential impacts of CVE-2020-37150?
The potential impacts of CVE-2020-37150 include unauthorized access to Wi-Fi networks and the disclosure of sensitive network information.
Is CVE-2020-37150 easily exploitable?
Yes, CVE-2020-37150 can be easily exploited by unauthenticated attackers accessing the vulnerable page.