CVE-2018-3954
published 2018-10-17CVE-2018-3954: Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command…
PriorityP345high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
3.38%
87.9th percentile
Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NVRAMData entered into the 'Router Name' input field through the web portal is submitted to apply.cgi as the value to the 'machine_name' POST parameter. When the 'preinit' binary receives the SIGHUP signal it enters a code path that calls a function named 'set_host_domain_name' from its libshared.so shared object.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linksys | e1200_firmware | — | — |
| linksys | e2500_firmware | — | — |
| linksys | eseries_e1200 | — | — |
| linksys | eseries_e2500 | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
blogs_talos·2018-10-16·CVSS 7.2
[HIGH] Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
## Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
Cisco Talos is disclosing several vulnerabilities in the operating system on the Linksys E Series of routers. Multiple exploitable OS command injection vulnerabilities exist in the Linksys E Series line of routers. An attacker can exploit these bugs by sending an authenticated HTTP request to the network configuration. An attacker could then gain the ability to arbitrarily execute code on the machine. The E Series is a line of routers for small and home offices that contain several features to make them easier to use. The routers are designed to connect home computers, internet-ready TVs, game consoles, smartphones and other Wi-Fi devices. Vulnerability Details TALOS-2018-0625 describes three related
Talos
Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
blogs_talos·2018-10-16·CVSS 7.2
[HIGH] Vulnerability Spotlight: Linksys ESeries Multiple OS Command Injection Vulnerabilities
Cisco Talos is disclosing several vulnerabilities in the operating system on the Linksys E Series of routers.
Multiple exploitable OS command injection vulnerabilities exist in the Linksys E Series line of routers. An attacker can exploit these bugs by sending an authenticated HTTP request to the network configuration. An attacker could then gain the ability to arbitrarily execute code on the machine.
The E Series is a line of routers for small and home offices that contain several features to make them easier to use. The routers are designed to connect home computers, internet-ready TVs, game consoles, smartphones and other Wi-Fi devices.
Vulnerability Details
TALOS-2018-0625 describes three related vulnerabilities: CVE-2018-3953, CVE-2018-3954 and CVE-2018-3955.
Many of the configur
2018-10-17
Published