Linksys E8450
cpe:2.3:h:linksys:e8450:*:*:*:*:*:*:*, +1 more
- FW_E8450_1.2.00.360516
A command injection vulnerability has been identified in the Linksys E8450 router, specifically in firmware version 1.2.00.360516. The issue arises in the JSON parsing function of the device's portal CGI script, where the 'userEmail' field can be manipulated to execute arbitrary commands on the system.
Exploitation of this vulnerability allows for unauthenticated command injection, where an attacker can execute arbitrary commands on the router's operating system.
To reproduce this vulnerability, send a JSON payload to the '/cgi-bin/portal.cgi' endpoint. The payload should include an 'action' field set to 'register_email', a 'page' field set to 'register_email_wizard', and a 'userEmail' field containing the crafted command injection payload. The 'id_email_check_btn' field can be left empty.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.