Edimax EW-7438RPn Mini
cpe:2.3:h:edimax:ew-7438rpn_mini:*:*:*:*:*:*:*, +1 more
- 1.23
- 1.27
A vulnerability in the Edimax EW-7438RPn Mini Wi-Fi range extender, specifically in version 1.27, allows unauthenticated attackers to access the /wizard_reboot.asp page in 'unsetup' mode. This access discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without authentication.
Exploitation of this vulnerability leads to unauthorized disclosure of the Wi-Fi password, allowing attackers to gain access to the wireless network.
The vulnerability can be reproduced by sending a GET request to the /wizard_reboot.asp page while the device is in 'unsetup' mode'. This can be done without any authentication, directly accessing the page to retrieve the Wi-Fi SSID and security key.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.