Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.
2019-11-21T15:15:13.887
2024-11-21T04:30:33.307
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:N
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linksys | velop_whw0303_firmware | 1.1.8.192419 | Yes |
Hardware | linksys | velop_whw0303 | - | No |
Operating System | linksys | velop_whw0302_firmware | 1.1.8.192419 | Yes |
Hardware | linksys | velop_whw0302 | - | No |
Operating System | linksys | velop_whw0301_firmware | 1.1.8.192419 | Yes |
Hardware | linksys | velop_whw0301 | - | No |