Linksys E1200
cpe:2.3:h:linksys:e1200:*:*:*:*:*:*:*, +1 more
- <= 2.0.04
A command injection vulnerability has been identified in Linksys E1000 devices running versions prior to 2.1.02, E1200 devices prior to 2.0.05, and E3200 devices running versions prior to 1.0.04. The issue arises in the apply.cgi file, where shell metacharacters in the ping_ip parameter can be exploited to inject and execute operating system commands. This vulnerability is accessible through TCP port 52000.
Exploitation of this vulnerability allows for OS command injection, where an attacker can execute arbitrary commands on the device's operating system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.