CVE-2009-5157

HIGH EXPLOITED

Linksys WAG54G2 1.00.10 - Authenticated Command Injection via setup.cgi c4_ping_ipaddr Variable

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2009-5157 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c4_ping_ipaddr variable.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://www.securityfocus.com/bid/35142
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.securityfocus.com/archive/1/503934

Scores

CVSS v3 8.8
EPSS 0.1294
EPSS Percentile 94.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2019-06-13
CWE
CWE-77
Status published
Products (1)
linksys/wag54g2_firmware 1.00.10
Published Jun 11, 2019
Tracked Since Feb 18, 2026