8.8

CVE-2024-25852

Exploit

Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.

Data is provided by the National Vulnerability Database (NVD)
LinksysRe7000 Firmware Version2.0.9
   LinksysRe7000 Version-
LinksysRe7000 Firmware Version2.0.11
   LinksysRe7000 Version-
LinksysRe7000 Firmware Version2.0.15
   LinksysRe7000 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 93.11% 0.998
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.