CVE-2020-37150
Unknown Unknown - Not Provided

Unauthorized Access in Edimax EW-7438RPn-v3 Exposes Wi-Fi Credentials

Vulnerability report for CVE-2020-37150, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-02-05

Last updated on: 2026-02-18

Assigner: VulnCheck

Description

Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without authentication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-02-05
Last Modified
2026-02-18
Generated
2026-07-26
AI Q&A
2026-02-05
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
edimax ew-7438rpn_mini_firmware 1.27

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Edimax EW-7438RPn-v3 Mini 1.27 device. It allows unauthenticated attackers to access a specific page (/wizard_reboot.asp) when the device is in unsetup mode. By sending a simple GET request to this page, attackers can retrieve sensitive information such as the Wi-Fi SSID and the wireless security key without needing any authentication.

Detection Guidance

I don't know

Impact Analysis

The vulnerability can lead to unauthorized disclosure of your wireless network's SSID and security key. This means attackers can gain access to your Wi-Fi network without permission, potentially allowing them to intercept network traffic, access connected devices, or use your network for malicious activities.

Compliance Impact

I don't know

Mitigation Strategies

I don't know

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2020-37150. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart