CVE-2020-37125: Edimax Ew-7438rpn Mini Firmware

Critical severity, CVSS 9.8. EPSS: 7.1% chance of exploitation in the next 30 days.

Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection payloads to download and execute malicious scripts on the device.

Affected products

  • Edimax Ew-7438rpn Mini Firmware: version 1.27 only

Published 2026-02-05. Last modified 2026-06-17.