Back to CVE List

CVE-2020-37150

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Vulnerability Description

Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without authentication.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-201
Source
NVD
Vendor
EDIMAX Technology
Product
EW-7438RPn Mini

External References

Discussion (0)

Add Comment

No comments yet. Be the first!