Vulnerability Details CVE-2020-37149
Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An attacker can trick an authenticated user into submitting a crafted form to the /goform/mp endpoint, resulting in arbitrary command execution on the device with the user's privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 4.2%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2020-37149
-
cpe:2.3:h:edimax:ew-7438rpn_mini:3
-
cpe:2.3:o:edimax:ew-7438rpn_mini_firmware:1.27