PT-2019-12359 · Linksys · Linksys Re6300+1
Rodney Beede
·
Publicado
2019-07-17
·
Atualizado
2020-08-24
·
CVE-2019-11535
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linksys WiFi extender products (RE6400 and RE6300) versions 1.2.04.022 and earlier
Description
The issue concerns unsanitized user input in the web interface, allowing for remote command execution. This enables an attacker to access system OS configurations and commands not intended for use beyond the web UI.
Recommendations
For Linksys WiFi extender products (RE6400 and RE6300) versions 1.2.04.022 and earlier, consider disabling remote access to the web interface until a fix is available. Restrict access to system OS configurations and commands to minimize the risk of exploitation.
Correção
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linksys Re6300
Linksys Re6400