Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 ssid1MACFilter os command injection
Vulnerability Description
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. This vulnerability affects the function ssid1MACFilter of the file /goform/ssid1MACFilter. The manipulation of the argument apselect_%d/newap_text_%d leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Linksys多款产品 命令注入漏洞
Vulnerability Description
Linksys RE6300等都是美国Linksys公司的产品。Linksys RE6300是一款无线网络信号扩展器。Linksys RE7000是一款无线信号扩展器。Linksys RE6250是一款无线扩展器。 Linksys多款产品存在命令注入漏洞,该漏洞源于文件/goform/ssid1MACFilter中参数apselect_%d/newap_text_%d的错误操作导致os命令注入。以下产品及版本受到影响:RE6500和RE6250和RE6300和RE6350和RE7000和RE9000 1.
CVSS Information
N/A
Vulnerability Type
N/A