← Back

Linksys

linksys

223 CVEs • 143 products

Products (143)

Click to collapse
Toggle
Wrt54g
wrt54g
Befsr41
befsr41
Ea6500
ea6500
Wap11
wap11
Befvp41
befvp41
Wag54gs
wag54gs
Befn2ps4
befn2ps4
Befsr81
befsr81
Befsr11
befsr11
Befsru31
befsru31
Befsx41
befsx41
Befw11s4
befw11s4
Wrt54gs
wrt54gs
Wet11
wet11
Wap55ag
wap55ag
Wvc11b
wvc11b
Wrt54g V5
wrt54g_v5
Spa941
spa941
Wrt54gl
wrt54gl
Wap400n
wap400n
Ea4500
ea4500
Ea6400
ea6400
E4200v2
e4200v2
Ea6300
ea6300
Ea6900
ea6900
Ea2700
ea2700
Ea3500
ea3500
Ea6200
ea6200
Ea6700
ea6700
Hpro200
hpro200
Befcmu10
befcmu10
Befsr41w
befsr41w
Rv082
rv082
Befsr41 V3
befsr41_v3
Befw11s4 V3
befw11s4_v3
Befw11s4 V4
befw11s4_v4
Rt31p2
rt31p2
Spa921
spa921
Wag200g
wag200g
Wrt54gc
wrt54gc
Wrt300n
wrt300n
Wrt350n
wrt350n
Wap4400n
wap4400n
Wap54gv3
wap54gv3
Wrt54gx
wrt54gx
Wvbr0 Firmware
wvbr0_firmware
Velop Firmware
velop_firmware
E5350 Firmware
e5350_firmware
E1000 Firmware
e1000_firmware
E1500 Firmware
e1500_firmware
E3000 Firmware
e3000_firmware

CVEs (223)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linksys
1Mr9600 Firmware
Nov 21, 2024
Apr 27, 2022
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share.
1Linksys
1Re6500 Firmware
Nov 21, 2024
Dec 26, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segmentation fault) via a long /goform/langSwitch langSelectionOnly parameter.
1Linksys
1Re6500 Firmware
Nov 21, 2024
Dec 26, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shell metacharacters in a filename to the upload_settings.cgi page.
1Linksys
1Re6500 Firmware
Nov 21, 2024
Dec 26, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program.
1Linksys
1Re6500 Firmware
Nov 21, 2024
Dec 26, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.
1Linksys
1Spa2102 Firmware
Nov 21, 2024
Feb 12, 2020
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force...Show more
The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.Show less
1Linksys
1Wrt310n Firmware
Nov 21, 2024
Feb 7, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Linksys WRT310Nv2 2.0.0.1 is vulnerable to XSS.
1Linksys
3Velop Whw0301 Firmware
Velop Whw0302 FirmwareVelop Whw0303 Firmware
Nov 21, 2024
Nov 21, 2019
N/A· v4
9.8 CRITICAL· v3
6.4 MEDIUM· v2
Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.
1Linksys
1Ea6500 Firmware
Nov 21, 2024
Oct 25, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share.
1Linksys
2Re6300 Firmware
Re6400 Firmware
Nov 21, 2024
Jul 17, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execution. An attacker can access system OS configurations and commands that...Show more
Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execution. An attacker can access system OS configurations and commands that are not intended for use beyond the web UI.Show less
1Linksys
1Wrt1900acs Firmware
Nov 21, 2024
Jun 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. An ability exists for an unauthenticated user to browse a confidential ui/1.0.99.187766/dynamic/js/setup.js.localized file on the router's webserver, al...Show more
An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. An ability exists for an unauthenticated user to browse a confidential ui/1.0.99.187766/dynamic/js/setup.js.localized file on the router's webserver, allowing for an attacker to identify possible passwords that the system uses to set the default guest network password. An attacker can use this list of 30 words along with a random 2 digit number to brute force their access onto a router's guest network.Show less
1Linksys
1Wag54g2 Firmware
Nov 21, 2024
Jun 11, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c4_ping_ipaddr variable.
1Linksys
1Wrt1900acs Firmware
Nov 21, 2024
Jun 6, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. A lack of encryption in how the user login cookie (admin-auth) is stored on a victim's computer results in the admin password being discoverable by a lo...Show more
An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. A lack of encryption in how the user login cookie (admin-auth) is stored on a victim's computer results in the admin password being discoverable by a local attacker, and usable to gain administrative access to the victim's router. The admin password is stored in base64 cleartext in an "admin-auth" cookie. An attacker sniffing the network at the time of login could acquire the router's admin password. Alternatively, gaining physical access to the victim's computer soon after an administrative login could result in compromise.Show less
1Linksys
2E1200 Firmware
E2500 Firmware
Nov 21, 2024
Oct 17, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04). Specially crafted entries to network conf...Show more
An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04). Specially crafted entries to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send an authenticated HTTP request to trigger this vulnerability. Data entered into the 'Domain Name' input field through the web portal is submitted to apply.cgi as the value to the 'wan_domain' POST parameter. The wan_domain data goes through the nvram_set process described above. When the 'preinit' binary receives the SIGHUP signal it enters a code path that calls a function named 'set_host_domain_name' from its libshared.so shared object.Show less
1Linksys
2E1200 Firmware
E2500 Firmware
Nov 21, 2024
Oct 17, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data p...Show more
Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NVRAMData entered into the 'Router Name' input field through the web portal is submitted to apply.cgi as the value to the 'machine_name' POST parameter. When the 'preinit' binary receives the SIGHUP signal it enters a code path that calls a function named 'set_host_domain_name' from its libshared.so shared object.Show less
1Linksys
2E1200 Firmware
E2500 Firmware
Nov 21, 2024
Oct 17, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data p...Show more
Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NVRAM. Data entered into the 'Router Name' input field through the web portal is submitted to apply.cgi as the value to the 'machine_name' POST parameter. When the 'preinit' binary receives the SIGHUP signal, it enters a code path that continues until it reaches offset 0x0042B5C4 in the 'start_lltd' function. Within the 'start_lltd' function, a 'nvram_get' call is used to obtain the value of the user-controlled 'machine_name' NVRAM entry. This value is then entered directly into a command intended to write the host name to a file and subsequently executed.Show less
1Linksys
1Velop Firmware
Nov 21, 2024
Sep 19, 2018
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts that can be discovered with binwalk on the f...Show more
Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts that can be discovered with binwalk on the firmware, but are not visible in the web interface). This occurs because shell metacharacters in the query string are mishandled by ShellExecute, as demonstrated by the zbtest.cgi?cmd=level&level= substring. This can also be exploited via CSRF.Show less
1Linksys
1Wvbr0 Firmware
May 13, 2026
Dec 21, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web man...Show more
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892.Show less
1Linksys
1Ea4500 Firmware
May 13, 2026
Aug 6, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery (CSRF) exists on Linksys EA4500 devices with Firmware Version before 2.1.41.164606, as demonstrated by a request to apply.cgi to disable SIP.
1Linksys
20E4200v2
E4200v2 FirmwareEa2700+17 more
May 6, 2026
Nov 1, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and...Show more
Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain sensitive information or modify data via a JNAP action in a JNAP/ HTTP request.Show less