PT-2022-22907 · Linksys · Linksys E5350 Wifi Router
Published
2022-09-12
·
Updated
2023-08-08
·
CVE-2022-35572
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Linksys E5350 WiFi Router version 1.0.00.037 and lower
Description
The issue concerns the /SysInfo.htm URI, which does not require a session ID. This web page calls the
show sysinfo function, retrieving sensitive information such as WPA passwords, SSIDs, MAC Addresses, serial numbers, WPS Pins, and hardware/firmware versions, and prints this information into the web page. This web page is accessible when remote management is enabled, allowing a user with access to the web interface to extract these secrets. If the device has remote management enabled and is connected directly to the internet, this issue is exploitable over the internet without interaction.Recommendations
For Linksys E5350 WiFi Router version 1.0.00.037 and lower, consider disabling remote management to minimize the risk of exploitation until a patch is available. As a temporary workaround, restrict access to the /SysInfo.htm URI to prevent unauthorized users from extracting sensitive information.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linksys E5350 Wifi Router