Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-37125. PoCs published by Wadeek.
AI-analyzed exploit summary This exploit demonstrates remote code execution (RCE) in Edimax EW-7438RPn-v3 Mini firmware versions 1.23 and 1.27 via command injection in the 'command' parameter of the '/goform/mp' endpoint. It includes methods for both setup and unsetup modes, with optional authentication bypass using default credentials.
Description
Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection payloads to download and execute malicious scripts on the device.
Exploits (1)
This exploit demonstrates remote code execution (RCE) in Edimax EW-7438RPn-v3 Mini firmware versions 1.23 and 1.27 via command injection in the 'command' parameter of the '/goform/mp' endpoint. It includes methods for both setup and unsetup modes, with optional authentication bypass using default credentials.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H