PT-2019-12359 · Linksys · Linksys Re6300+1
Rodney Beede
·
Published
2019-07-17
·
Updated
2020-08-24
·
CVE-2019-11535
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linksys WiFi extender products (RE6400 and RE6300) versions 1.2.04.022 and earlier
Description
The issue concerns unsanitized user input in the web interface, allowing for remote command execution. This enables an attacker to access system OS configurations and commands not intended for use beyond the web UI.
Recommendations
For Linksys WiFi extender products (RE6400 and RE6300) versions 1.2.04.022 and earlier, consider disabling remote access to the web interface until a fix is available. Restrict access to system OS configurations and commands to minimize the risk of exploitation.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linksys Re6300
Linksys Re6400