PT-2024-21165 · Linksys · Linksys Re7000

Published

2024-03-28

·

Updated

2024-08-14

·

CVE-2024-25852

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linksys RE7000 versions 2.0.9 through 2.0.15
Description The issue concerns a command execution vulnerability in the AccessControlList parameter of the access control function point. This vulnerability can be exploited by an attacker to obtain device administrator rights.
Recommendations For versions 2.0.9 through 2.0.15, consider restricting access to the AccessControlList parameter in the access control function point until a patch is available. As a temporary workaround, avoid using the AccessControlList parameter in the affected access control function point to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-15401
CVE-2024-25852

Affected Products

Linksys Re7000