CVE-2020-37097

Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive information including WiFi network name and plaintext password stored in device configuration variables.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:edimax:ew-7438rpn_mini_firmware:1.13:*:*:*:*:*:*:*
cpe:2.3:h:edimax:ew-7438rpn_mini:-:*:*:*:*:*:*:*

History

20 Feb 2026, 15:45

Type Values Removed Values Added
Summary
  • (es) Edimax EW-7438RPn 1.13 contiene una vulnerabilidad de revelación de información que expone detalles de configuración de la red WiFi a través del archivo wlencrypt_wiz.asp. Los atacantes pueden acceder al script para recuperar información sensible, incluyendo el nombre de la red WiFi y la contraseña en texto plano, almacenados en variables de configuración del dispositivo.
First Time Edimax ew-7438rpn Mini
Edimax
Edimax ew-7438rpn Mini Firmware
CPE cpe:2.3:o:edimax:ew-7438rpn_mini_firmware:1.13:*:*:*:*:*:*:*
cpe:2.3:h:edimax:ew-7438rpn_mini:-:*:*:*:*:*:*:*
References () https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/global/wi-fi_range_extenders_n300/ew-7438rpn_mini/ - () https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/global/wi-fi_range_extenders_n300/ew-7438rpn_mini/ - Product
References () https://www.exploit-db.com/exploits/48365 - () https://www.exploit-db.com/exploits/48365 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/edimax-ew-rpn-information-disclosure-wifi-password - () https://www.vulncheck.com/advisories/edimax-ew-rpn-information-disclosure-wifi-password - Broken Link

03 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 22:16

Updated : 2026-02-20 15:45


NVD link : CVE-2020-37097

Mitre link : CVE-2020-37097

CVE.ORG link : CVE-2020-37097


JSON object : View

Products Affected

edimax

  • ew-7438rpn_mini_firmware
  • ew-7438rpn_mini
CWE
CWE-522

Insufficiently Protected Credentials