PT-2018-13949 · Linksys · Linksys Velop

Published

2018-09-19

·

Updated

2019-10-03

·

CVE-2018-17208

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linksys Velop version 1.1.2.187020
Description The issue allows unauthenticated command injection, providing an attacker with full root access. This can be achieved via the "cgi-bin/zbtest.cgi" or "cgi-bin/zbtest2.cgi" API endpoints. The vulnerability occurs because shell metacharacters in the query string are mishandled by the ShellExecute function. For example, the zbtest.cgi?cmd=level&level= substring demonstrates this mishandling. Additionally, this issue can be exploited via CSRF.
Recommendations For Linksys Velop version 1.1.2.187020, as a temporary workaround, consider restricting access to the "cgi-bin/zbtest.cgi" and "cgi-bin/zbtest2.cgi" API endpoints to minimize the risk of exploitation. Avoid using the cmd and level variables in the query string of the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17208

Affected Products

Linksys Velop