Insecure Permissions in Linksys Velop WiFi 5 by Linksys
CVE-2024-36821

6.8MEDIUM

Key Information:

Vendor
Linksys
Vendor
CVE Published:
11 June 2024

Summary

The Linksys Velop WiFi 5 (WHW01v1) version 1.1.13.202617 is susceptible to a vulnerability that permits attackers to escalate their privileges from Guest to root. This loophole in permissions may allow unauthorized users to gain elevated access, posing a significant threat to network security. It is crucial for users to review and apply the latest security updates to safeguard their systems against potential exploitation.

References

EPSS Score

14% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.