CVE-2020-37125
Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection payloads to download and execute malicious scripts on the device.
| CWE | CWE-78 |
| Vendor | edimax technology |
| Product | ew-7438rpn mini |
| Published | Feb 5, 2026 |
| Last Updated | Mar 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for edimax technology ew-7438rpn mini
Be the first to know when new critical vulnerabilities affecting edimax technology ew-7438rpn mini are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
EDIMAX Technology / EW-7438RPn Mini
1.27
References
Credits
Wadeek