PT-2020-7412 · Cisco · Cisco Linksys E4200
Published
2020-02-04
·
Updated
2020-02-07
·
CVE-2013-2678
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Cisco Linksys E4200 version 1.0.05 Build 7
Description:
The issue allows remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the "apply.cgi" script using the
submit type parameter.Recommendations:
For Cisco Linksys E4200 version 1.0.05 Build 7, consider restricting access to the "apply.cgi" script as a temporary workaround until a patch is available. Avoid using the
submit type parameter in the affected script until the issue is resolved.Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Linksys E4200