CRITICAL🇵🇱 Wersja polska

CVE-2020-37125

CVSS 9.3v4.0pub. 2026-02-05upd. 2026-02-18

Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection payloads to download and execute malicious scripts on the device.

🤖 AI Analysis
How it works

A command injection vulnerability (CWE-78) exists in the unauthenticated /goform/mp endpoint. The attacker sends a crafted POST request containing a payload with injected system commands. The device processes the input without proper validation and sanitization, passing it directly to the system command interpreter. This allows malicious scripts to be downloaded and executed on the device.

Impact

An unauthorized remote attacker can execute arbitrary system commands on the network device, leading to complete takeover of control, ability to install malicious software, and potential use of the device as an entry point to the internal network.

Mitigation & patch

Apply patches available from the manufacturer according to the references. As an immediate workaround, it is recommended to isolate the device from public network access, restrict access to the management interface only to trusted hosts, and monitor network traffic directed to the /goform/mp endpoint.

Who is affected

Edimax EW-7438RPn-v3 Mini with firmware version 1.27

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Edimax Ew 7438rpn Mini

    HW
    Edimax
    3
  • Edimax Ew 7438rpn Mini Firmware

    OS
    Edimax
    1.27
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth BypassCommand Injection
CWE
References

Related vulnerabilities

CVE-2025-34024CRITICAL9.4PL ✓same product

OS Command Injection w Edimax EW-7438RPn Mini — wykonanie poleceń jako root

CVE-2025-34029CRITICAL9.4PL ✓same product

Command injection w Edimax EW-7438RPn Mini — wykonanie poleceń jako root

CVE-2020-37150HIGH8.7same product

Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unset...

CVE-2020-37097HIGH8.7same product

Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuratio...

CVE-2016-10863HIGH8.8same product

Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.