nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-27497 CVE-2024-27497
HIGHNuclei
Linksys E2000 Ver.1.0.06 build 1 Authentication Bypass
Record summary
CVE-2024-27497 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.
Description
Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 19, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 16, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
e2000_firmwareBrowse linksys / e2000_firmwareDefault status: unknown | CVE List | 1.0.06 | affected |
Nuclei templates
1ProjectDiscoveryHIGHLinksys E2000 1.0.06 position.js Improper Authentication
Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.
Impact
Successful exploitation could lead to unauthorized access to the device.
Remediation
Upgrade to a patched version of the firmware to mitigate the vulnerability.
AuthorsDhiyaneshDk
Template tagscvecve2024linksysauth-bypassvkevvuln
Shodan: product:"Linksys E2000 WAP http config"
FOFA: app="LINKSYS-E2000"
https://warp-desk-89d.notion.site/Linksys-E-2000-efcd532d8dcf4710a4af13fca131a5b8 https://nvd.nist.gov/vuln/detail/CVE-2024-27497 https://github.com/Ostorlab/KEV https://github.com/fkie-cad/nvd-json-data-feeds
Source: ProjectDiscovery
References
2warp-desk-89d.notion.site
https://warp-desk-89d.notion.site/Linksys-E-2000-efcd532d8dcf4710a4af13fca131a5b8