CVE-2020-37150
7.5Edimax · EW-7438RPn-v3 Mini
The Edimax EW-7438RPn-v3 Mini allows unauthenticated attackers to disclose the Wi-Fi SSID and security key via the /wizard_reboot.asp page.
Executive summary
An unauthenticated information disclosure vulnerability in the Edimax EW-7438RPn-v3 Mini allows remote attackers to access sensitive Wi-Fi credentials.
Vulnerability
The device contains an information disclosure flaw in the /wizard_reboot.asp endpoint, which permits unauthenticated users to retrieve wireless network settings, including the security key, through a simple GET request.
Business impact
Successful exploitation allows unauthorized parties to obtain the Wi-Fi security key, effectively bypassing wireless network access controls. This exposure facilitates unauthorized network entry, potential data interception, and lateral movement within the environment. Given the CVSS score of 7.5, this vulnerability represents a high risk to the confidentiality of network communications and organizational security posture.
Remediation
Immediate Action: Consult the official Edimax support portal to determine if a firmware update is available for your specific hardware unit and apply it immediately. If no update is available, isolate the device from public-facing networks.
Proactive Monitoring: Regularly audit network logs for unauthorized access attempts directed at the /wizard_reboot.asp or /goform/mp endpoints.
Compensating Controls: Deploy a Web Application Firewall or restrict access to the device management interface to trusted internal IP addresses only.
Exploitation status
Public Exploit Available: Yes, a functional exploit is available via ExploitDB (EDB-ID 48318).
Analyst recommendation
The presence of a published exploit, combined with the ease of access for unauthenticated attackers, makes this a high-priority risk. Administrators must prioritize updating the firmware or physically isolating affected devices to prevent unauthorized credential harvesting and subsequent network compromise.
More Edimax CVEs
Sources
Originally found and disclosed by Wadeek, per the CVE Program record.