CVE-2020-37150

7.5

Edimax · EW-7438RPn-v3 Mini

The Edimax EW-7438RPn-v3 Mini allows unauthenticated attackers to disclose the Wi-Fi SSID and security key via the /wizard_reboot.asp page.

Executive summary

An unauthenticated information disclosure vulnerability in the Edimax EW-7438RPn-v3 Mini allows remote attackers to access sensitive Wi-Fi credentials.

Vulnerability

The device contains an information disclosure flaw in the /wizard_reboot.asp endpoint, which permits unauthenticated users to retrieve wireless network settings, including the security key, through a simple GET request.

Business impact

Successful exploitation allows unauthorized parties to obtain the Wi-Fi security key, effectively bypassing wireless network access controls. This exposure facilitates unauthorized network entry, potential data interception, and lateral movement within the environment. Given the CVSS score of 7.5, this vulnerability represents a high risk to the confidentiality of network communications and organizational security posture.

Remediation

Immediate Action: Consult the official Edimax support portal to determine if a firmware update is available for your specific hardware unit and apply it immediately. If no update is available, isolate the device from public-facing networks.

Proactive Monitoring: Regularly audit network logs for unauthorized access attempts directed at the /wizard_reboot.asp or /goform/mp endpoints.

Compensating Controls: Deploy a Web Application Firewall or restrict access to the device management interface to trusted internal IP addresses only.

Exploitation status

Public Exploit Available: Yes, a functional exploit is available via ExploitDB (EDB-ID 48318).

Analyst recommendation

The presence of a published exploit, combined with the ease of access for unauthenticated attackers, makes this a high-priority risk. Administrators must prioritize updating the firmware or physically isolating affected devices to prevent unauthorized credential harvesting and subsequent network compromise.

More Edimax CVEs

Sources

Originally found and disclosed by Wadeek, per the CVE Program record.