Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2022-38841

Severity
8.8HIGH
EPSS
3.2%
top 12.93%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedApr 16

Description

Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-rjm4-59w8-7r6f: Linksys AX3200 12023-04-16
CVEList
CVE-2022-38841: Linksys AX3200 12023-04-16

💥Exploits & PoCs

1
Exploit-DB
Linksys AX3200 V1.1.00 - Command Injection2023-03-22
CVE-2022-38841 (HIGH CVSS 8.8) | Linksys AX3200 1.1.00 is vulnerable | cvebase.io