8.8
CVE-2024-25852
- EPSS 93.11%
- Published 11.04.2024 21:15:07
- Last modified 17.06.2025 20:50:31
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.
Data is provided by the National Vulnerability Database (NVD)
Linksys ≫ Re7000 Firmware Version2.0.9
Linksys ≫ Re7000 Firmware Version2.0.11
Linksys ≫ Re7000 Firmware Version2.0.15
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 93.11% | 0.998 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.