CVE-2020-37097

Severity CVSS v4.0:
HIGH
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
03/02/2026
Last modified:
20/02/2026

Description

Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive information including WiFi network name and plaintext password stored in device configuration variables.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:edimax:ew-7438rpn_mini_firmware:1.13:*:*:*:*:*:*:*
cpe:2.3:h:edimax:ew-7438rpn_mini:-:*:*:*:*:*:*:*