High severity8.1NVD Advisory· Published Feb 5, 2026· Updated Jun 17, 2026
CVE-2020-37149
CVE-2020-37149
Description
Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An attacker can trick an authenticated user into submitting a crafted form to the /goform/mp endpoint, resulting in arbitrary command execution on the device with the user's privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:o:edimax:ew-7438rpn_mini_firmware:1.27:*:*:*:*:*:*:*
1.27+ 1 more
- (no CPE)range: 1.27
- (no CPE)range: 1.23
- Range: 1.27
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/48318nvdExploitThird Party AdvisoryVDB Entry
- www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/global/wi-fi_range_extenders_n300/ew-7438rpn_mini/nvdProduct
- www.vulncheck.com/advisories/edimax-technology-ew-rpn-mini-cross-site-request-forgery-csrf-to-command-executionnvdBroken Link
News mentions
0No linked articles in our index yet.