Record summary

CVE-2024-27497 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 19, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 16, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Default status: unknown

CVE List1.0.06affected

Nuclei templates

1
ProjectDiscoveryHIGHLinksys E2000 1.0.06 position.js Improper Authentication

Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.

Impact

Successful exploitation could lead to unauthorized access to the device.

Remediation

Upgrade to a patched version of the firmware to mitigate the vulnerability.

AuthorsDhiyaneshDk
Template tagscvecve2024linksysauth-bypassvkevvuln
Shodan: product:"Linksys E2000 WAP http config"
FOFA: app="LINKSYS-E2000"

Source: ProjectDiscovery

References

2