cbcvebase.
CVE-2017-10677
published 2017-08-06

CVE-2017-10677: Cross-Site Request Forgery (CSRF) exists on Linksys EA4500 devices with Firmware Version before 2.1.41.164606, as demonstrated by a request to apply.cgi to…

high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
Cross-Site Request Forgery (CSRF) exists on Linksys EA4500 devices with Firmware Version before 2.1.41.164606, as demonstrated by a request to apply.cgi to disable SIP.

Affected

1 ranges
VendorProductVersion rangeFixed in
linksysea4500_firmware<= 2.0.36