Edimax EW-7438RPn Mini
cpe:2.3:h:edimax:ew-7438rpn_mini:*:*:*:*:*:*:*, +1 more
- 1.13
A cross-site request forgery (CSRF) vulnerability has been identified in the Edimax EW-7438RPn Mini Wi-Fi extender, specifically in version 1.13. This vulnerability allows attackers to manipulate MAC filtering settings by tricking users into adding unauthorized MAC addresses to the device's filtering rules without their knowledge. The issue arises in the MAC filtering configuration interface, where crafted web pages can exploit the vulnerability.
Exploitation of this vulnerability allows for unauthorized modification of MAC filtering rules, potentially leading to unauthorized network access or disruption of network services.
To reproduce this vulnerability, a CSRF exploit can be crafted that targets the MAC filtering configuration interface. The exploit must be delivered to the user in a way that tricks them into submitting the form without their consent. This can be done by hosting the exploit on a malicious web page that the user is likely to visit. Once the page is loaded, the form is automatically submitted, adding the specified MAC address to the device's filtering rules.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.