CVE-2020-37150: Edimax Ew-7438rpn Mini Firmware
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without authentication.
Affected products
- Edimax Ew-7438rpn Mini Firmware: version 1.27 only
Published 2026-02-05. Last modified 2026-06-17.