Уязвимость была обнаружена в Linksys RE7000 2.0.15. Это влияет на функцию Platform_event_pingTest файла /cgi-bin/json.cgi?PingTest компонента PingTest Handler. Манипулирование аргументом pingTestIp/pingTestPktSize/pingTestTimes приводит к внедрению команды ОС.
Атака может быть запущена удаленно. Эксплойт теперь общедоступен и может быть использован.
Показать оригинальное описание (EN)
A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection. The attack can be launched remotely. The exploit is now public and may be used.
Характеристики атаки
Последствия
Строка CVSS v4.0