ZeroHour

CVE-2019-11535

CVSS 3.0
9.8 critical
EPSS
5%p92
Published
()
Modified
Description

Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execution. An attacker can access system OS configurations and commands that are not intended for use beyond the web UI.

Vendors
linksys
Products
re6400 firmware, re6300 firmware
Weakness
CWE-77
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.