CVE-2017-17411
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892.
Affected (1)
Products: Linksys: Wvbr0 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.41 |
| Running on/with | Platform Versions |
|---|---|
Linksys Wvbr0 | All versions |
References (10)
Source: zdi-disclosures@trendmicro.com
Third Party AdvisoryVDB Entry
Source: zdi-disclosures@trendmicro.com
ExploitThird Party Advisory
Source: zdi-disclosures@trendmicro.com
ExploitThird Party AdvisoryVDB Entry
Source: zdi-disclosures@trendmicro.com
ExploitThird Party AdvisoryVDB Entry
Source: zdi-disclosures@trendmicro.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.