PT-2021-16511 · Belkin · Belkin Linksys Wrt160Nl

CVE-2021-25310

·

Published

2021-02-02

·

Updated

2024-08-03

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Belkin Linksys WRT160NL version 1.0.04.002 US 20130619
Description: The administration web interface on Belkin Linksys WRT160NL devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui language POST parameter to the "apply.cgi" form endpoint. This occurs in the do upgrade post function in mini httpd. The vulnerability only affects products that are no longer supported by the maintainer.
Recommendations: As a temporary workaround, consider disabling the do upgrade post function in mini httpd until a patch is available. Restrict access to the "apply.cgi" form endpoint to minimize the risk of exploitation. Avoid using the ui language parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25310

Affected Products

Belkin Linksys Wrt160Nl