VU#447516Third-party advisory
http://www.kb.cert.org/vuls/id/447516 CVE-2014-8244
linksys ea3500_firmware Exposure of Sensitive Information to an Unauthorized Actor
Record summary
CVE-2014-8244 has a selected CVSS score of 7.5; EIP currently links 1 repository PoC.
Description
Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain sensitive information or modify data via a JNAP action in a JNAP/ HTTP request.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 12, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ea3500_firmwareBrowse linksys / ea3500_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubJollyJumbuckk/LinksysLeaksRepository PoCby JollyJumbuckkStars: 6Not analyzed5 files
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-8244