High severity7.5NVD Advisory· Published Feb 5, 2026· Updated Jun 17, 2026
CVE-2020-37150
CVE-2020-37150
Description
Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:edimax:ew-7438rpn_mini_firmware:1.27:*:*:*:*:*:*:*
<=1.27+ 1 more
- (no CPE)range: <=1.27
- (no CPE)range: 1.23
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/48318nvdExploitThird Party AdvisoryVDB Entry
- www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/global/wi-fi_range_extenders_n300/ew-7438rpn_mini/nvdProduct
- www.vulncheck.com/advisories/edimax-technology-ew-rpn-mini-unauthorized-access-wi-fi-password-disclosurenvdBroken Link
News mentions
0No linked articles in our index yet.