Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface. Attackers can craft malicious web pages to trick users into adding unauthorized MAC addresses to the device's filtering rules without their consent.
References
| Link | Resource |
|---|---|
| https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/global/wi-fi_range_extenders_n300/ew-7438rpn_mini/ | Product |
| https://www.exploit-db.com/exploits/48366 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/edimax-ew-rpn-cross-site-request-forgery-mac-filtering | Broken Link |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-02-03 22:16
Updated : 2026-02-20 15:37
NVD link : CVE-2020-37096
Mitre link : CVE-2020-37096
CVE.ORG link : CVE-2020-37096
JSON object : View
Products Affected
edimax
- ew-7438rpn_mini_firmware
- ew-7438rpn_mini
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
