Linksys E7350
cpe:2.3:h:linksys:e7350:*:*:*:*:*:*:*, +1 more
- 1.1.00.032
A command injection vulnerability has been identified in the Linksys E7350 router, specifically in firmware version 1.1.00.032. The issue arises in the 'vif_enable' function within the '/usr/lib/lua/luci/controller/mtkwifi.lua' file, where the 'iface' parameter can be manipulated to execute arbitrary commands.
Exploitation of this vulnerability allows for command injection, where an attacker can execute arbitrary commands on the router's operating system.
To reproduce this vulnerability, send a GET request to the '/cgi-bin/luci/admin/mtk/wifi/vif_enable/' endpoint, including a command injection payload in the 'iface' parameter. The injected command will be executed on the router, and the results can be observed in the response.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.