CVE-2024-25852
Linksys RE7000 AccessControlList Vulnerability
Record summary
CVE-2024-25852 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.
Description
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 14, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
RE7000Browse Linksys / RE7000 | VulnCheck | Version data not supplied | |
re7000_firmwareBrowse linksys / re7000_firmwareDefault status: unknown | CVE List | 2.0.9 | affected |
| 2.0.11 | affected | ||
| 2.0.15 | affected | ||
Nuclei templates
1ProjectDiscoveryHIGHLinksys RE7000 - Command Injection
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point
Impact
An attacker can use the vulnerability to obtain device administrator rights.
Remediation
Apply the latest security patches and updates from the vendor to address this vulnerability.
Source: ProjectDiscovery