8.8
CVE-2024-25852
- EPSS 16.52%
- Veröffentlicht 11.04.2024 21:15:07
- Zuletzt bearbeitet 17.06.2025 20:50:31
- Erkennungen
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linksys ≫ Re7000 Firmware Version 2.0.9
Linksys ≫ Re7000 Firmware Version 2.0.11
Linksys ≫ Re7000 Firmware Version 2.0.15
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 16.52% | 0.966 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://github.com/ZackSecurity/VulnerReport/blob/cve/Linksys/1.md
https://immense-mirror-b42.notion.site/Linksys-RE7000-command-injection-vulnerability-c1a47abf5e8d4dd0934d20d77da930bd