PT-2022-22907 · Linksys · Linksys E5350 Wifi Router

Published

2022-09-12

·

Updated

2023-08-08

·

CVE-2022-35572

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linksys E5350 WiFi Router version 1.0.00.037 and lower
Description The issue concerns the /SysInfo.htm URI, which does not require a session ID. This web page calls the show sysinfo function, retrieving sensitive information such as WPA passwords, SSIDs, MAC Addresses, serial numbers, WPS Pins, and hardware/firmware versions, and prints this information into the web page. This web page is accessible when remote management is enabled, allowing a user with access to the web interface to extract these secrets. If the device has remote management enabled and is connected directly to the internet, this issue is exploitable over the internet without interaction.
Recommendations For Linksys E5350 WiFi Router version 1.0.00.037 and lower, consider disabling remote management to minimize the risk of exploitation until a patch is available. As a temporary workaround, restrict access to the /SysInfo.htm URI to prevent unauthorized users from extracting sensitive information.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-35572

Affected Products

Linksys E5350 Wifi Router