Описание
Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without authentication.
Ссылки
- Product
- ExploitThird Party AdvisoryVDB Entry
- Broken Link
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:edimax:ew-7438rpn_mini_firmware:1.27:*:*:*:*:*:*:*
cpe:2.3:h:edimax:ew-7438rpn_mini:3:*:*:*:*:*:*:*
EPSS
Процентиль: 49%
0.00709
Низкий
7.5 High
CVSS3
Дефекты
CWE-201
Связанные уязвимости
CVSS3: 7.5
github
5 месяцев назад
Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without authentication.
EPSS
Процентиль: 49%
0.00709
Низкий
7.5 High
CVSS3
Дефекты
CWE-201