PT-2021-16511 · Belkin · Belkin Linksys Wrt160Nl

Published

2021-02-02

·

Updated

2024-08-03

·

CVE-2021-25310

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Belkin Linksys WRT160NL version 1.0.04.002 US 20130619
Description: The administration web interface on Belkin Linksys WRT160NL devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui language POST parameter to the "apply.cgi" form endpoint. This occurs in the do upgrade post function in mini httpd. The vulnerability only affects products that are no longer supported by the maintainer.
Recommendations: As a temporary workaround, consider disabling the do upgrade post function in mini httpd until a patch is available. Restrict access to the "apply.cgi" form endpoint to minimize the risk of exploitation. Avoid using the ui language parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-25310

Affected Products

Belkin Linksys Wrt160Nl