Command Injection Vulnerability in Linksys E7350 Router
CVE-2024-57227
8HIGH
Summary
The Linksys E7350 router version 1.1.00.032 is susceptible to a command injection vulnerability stemming from the ifname parameter in the apcli_do_enr_pbc_wps function. This flaw allows an attacker to execute arbitrary commands on the device, which could lead to unauthorized access and control over the network settings. Proper security measures and updates are essential to mitigate risks associated with this vulnerability.
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published