CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Edimax 1Ew 7438rpn Mini Firmware Feb 18, 2026 Feb 5, 2026 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by send...Show more |
1Edimax 1Ew 7438rpn Mini Firmware Feb 18, 2026 Feb 5, 2026 5.1 MEDIUM· v4 8.8 HIGH· v3 N/A· v2 Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An attacker can trick an authenticated user into submitting a crafted form to the /goform/mp endpoint,...Show more |
1Edimax 1Ew 7438rpn Mini Firmware Feb 18, 2026 Feb 5, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability b...Show more |
1Edimax 1Ew 7438rpn Mini Firmware Feb 20, 2026 Feb 3, 2026 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive informatio...Show more |
1Edimax 1Ew 7438rpn Mini Firmware Feb 20, 2026 Feb 3, 2026 5.1 MEDIUM· v4 4.3 MEDIUM· v3 N/A· v2 Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface. Attackers can craft malicious web pages to trick users into adding unauthorized MAC addresses to th...Show more |
1Edimax 1Ew 7438rpn Mini Firmware Nov 20, 2025 Jun 20, 2025 9.4 CRITICAL· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscmd.asp form handler. The /goform/formSysCmd endpoint exposes a system command interface through the s...Show more |
1Edimax 1Ew 7438rpn Mini Firmware Nov 20, 2025 Jun 20, 2025 9.4 CRITICAL· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint improperly handles user-supplied input to the command parameter....Show more |
1Edimax 27237rpd Firmware Ew 7438rpn Mini FirmwareNov 21, 2024 Aug 8, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure. |