A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute OS commands with root privileges.
2024-08-19T16:15:08.740
2024-08-20T16:18:24.300
Analyzed
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linksys | e1500_firmware | 1.0.06.001 | Yes |
Hardware | linksys | e1500 | - | No |