VulnerabilityAnalyzed
CVE-2020-37096
Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface.
MEDIUM 5.1EPSS 0.15%
Does this matter?
Lower severity and a low EPSS score (0.15%). Track it; it rarely justifies an emergency change on its own.
Description
Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface. Attackers can craft malicious web pages to trick users into adding unauthorized MAC addresses to the device's filtering rules without their consent.
- CVSS 4.0
- 5.1 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.15% probability · 5th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- edimax/ew-7438rpn mini firmware
- Source
- disclosure@vulncheck.com
References
- https://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/global/wi-fi_range_extenders_n300/ew-7438rpn_mini/Product
- https://www.exploit-db.com/exploits/48366Exploit, Third Party Advisory, VDB Entry
- https://www.vulncheck.com/advisories/edimax-ew-rpn-cross-site-request-forgery-mac-filteringBroken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.