Record summary

CVE-2024-25852 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 14, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Default status: unknown

CVE List2.0.9affected
2.0.11affected
2.0.15affected

Nuclei templates

1
ProjectDiscoveryHIGHLinksys RE7000 - Command Injection

Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point

Impact

An attacker can use the vulnerability to obtain device administrator rights.

Remediation

Apply the latest security patches and updates from the vendor to address this vulnerability.

Authorss4e-io
Template tagscvecve2024unauthinjectionvkevvuln

Source: ProjectDiscovery

References

3