CVE-2024-42633

A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute OS commands with root privileges.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:linksys:e1500_firmware:1.0.06.001:*:*:*:*:*:*:*
cpe:2.3:h:linksys:e1500:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-08-19 16:15

Updated : 2024-08-20 16:18


NVD link : CVE-2024-42633

Mitre link : CVE-2024-42633

CVE.ORG link : CVE-2024-42633


JSON object : View

Products Affected

linksys

  • e1500
  • e1500_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')