PT-2024-10255 · Linksys · Linksys E8450

Wood1314

·

Published

2024-12-26

·

Updated

2025-01-22

·

CVE-2024-57542

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linksys E8450 version 1.2.00.360516
Description A command injection issue was discovered, allowing attackers to inject malicious commands via the id email check btn field. This could potentially grant unauthorized access or control. The vulnerability is related to the lack of protection of the web page structure in the Linksys E8450 Wi-Fi router's firmware.
Recommendations For version 1.2.00.360516, update to a newer version to prevent potential exploitation. As a temporary workaround, consider restricting access to the id email check btn field until a patch is available.

Exploit

Fix

XSS

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-00652
CVE-2024-57542

Affected Products

Linksys E8450