CVE-2020-37096
MEDIUMEdimax EW-7438RPn 1.13 - Cross-Site Request Forgery in MAC Filtering Configuration
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37096. PoCs published by Besim.
AI-analyzed exploit summary This is a CSRF PoC targeting Edimax EW-7438RPn's MAC filtering feature. It submits a crafted form to add a MAC address to the filter list without user interaction.
Description
Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface. Attackers can craft malicious web pages to trick users into adding unauthorized MAC addresses to the device's filtering rules without their consent.
Exploits (1)
exploitdb
WORKING POC
by Besim · textwebappshardware
https://www.exploit-db.com/exploits/48366
This is a CSRF PoC targeting Edimax EW-7438RPn's MAC filtering feature. It submits a crafted form to add a MAC address to the filter list without user interaction.
Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target:
Edimax EW-7438RPn 1.13
No auth needed
Prerequisites:
Victim must be authenticated to the router's web interface · Attacker must trick victim into visiting the malicious page
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (3)
Core 3
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/48366
Various Sources product
https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/global/wi-fi_range_extenders_n300/ew-7438rpn_mini/
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/edimax-ew-rpn-cross-site-request-forgery-mac-filtering
Scores
CVSS v3
5.3
EPSS
0.0014
EPSS Percentile
4.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-352
Status
published
Products (1)
edimax/ew-7438rpn_mini_firmware
1.13
Published
Feb 03, 2026
Tracked Since
Feb 18, 2026