PT-2018-2661 · Linksys · Linksys E1200+1

Published

2018-07-09

·

Updated

2023-04-26

·

CVE-2018-3954

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linksys E1200 versions 2.0.09 and earlier Linksys E2500 versions 3.0.04 and earlier
Description The issue exists due to improper filtering of data passed to and retrieved from NVRAM, allowing for OS command injection. Data entered into the 'Router Name' input field through the web portal is submitted to apply.cgi as the value to the machine name POST parameter. This can be exploited by a remote attacker to execute arbitrary commands.
Recommendations For Linksys E1200 version 2.0.09, update to a newer version to mitigate the risk. For Linksys E2500 version 3.0.04, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the apply.cgi endpoint and limiting input to the machine name parameter to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2019-01293
CVE-2018-3954

Affected Products

Linksys E1200
Linksys E2500