PT-2024-10255 · Linksys · Linksys E8450

·

CVE-2024-57542

·

Published

2024-12-26

·

Updated

2025-01-22

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linksys E8450 version 1.2.00.360516
Description A command injection issue was discovered, allowing attackers to inject malicious commands via the id email check btn field. This could potentially grant unauthorized access or control. The vulnerability is related to the lack of protection of the web page structure in the Linksys E8450 Wi-Fi router's firmware.
Recommendations For version 1.2.00.360516, update to a newer version to prevent potential exploitation. As a temporary workaround, consider restricting access to the id email check btn field until a patch is available.

Exploit

Fix

XSS

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00652
CVE-2024-57542

Affected Products

Linksys E8450