PT-2024-10255 · Linksys · Linksys E8450
Wood1314
·
Published
2024-12-26
·
Updated
2025-01-22
·
CVE-2024-57542
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linksys E8450 version 1.2.00.360516
Description
A command injection issue was discovered, allowing attackers to inject malicious commands via the
id email check btn field. This could potentially grant unauthorized access or control. The vulnerability is related to the lack of protection of the web page structure in the Linksys E8450 Wi-Fi router's firmware.Recommendations
For version 1.2.00.360516, update to a newer version to prevent potential exploitation. As a temporary workaround, consider restricting access to the
id email check btn field until a patch is available.Exploit
Fix
XSS
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linksys E8450