CVE-2020-37125
CRITICALEdimax EW-7438RPn-v3 Mini 1.27 - RCE
Title source: llmDescription
Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection payloads to download and execute malicious scripts on the device.
Exploits (1)
References (3)
Scores
CVSS v3
9.8
EPSS
0.0131
EPSS Percentile
79.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-78
Status
published
Affected Products (1)
edimax/ew-7438rpn_mini_firmware
Timeline
Published
Feb 05, 2026
Tracked Since
Feb 18, 2026