On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c4_ping_ipaddr variable.
2019-06-11T21:29:00.287
2024-11-21T01:11:17.727
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linksys | wag54g2_firmware | 1.00.10 | Yes |
Hardware | linksys | wag54g2 | - | No |