Linksys E8450
cpe:2.3:h:linksys:e8450:*:*:*:*:*:*:*, +1 more
- FW_E8450_1.2.00.360516
A command injection vulnerability has been identified in the Linksys E8450 router, specifically in firmware version 1.2.00.360516. The issue arises in the 'id_email_check_btn' field, where user-supplied input is improperly sanitized before being passed to the system function, allowing for arbitrary command execution.
Exploitation of this vulnerability allows for unauthenticated command injection, where an attacker can execute arbitrary commands on the router's operating system.
To reproduce this vulnerability, send a JSON payload to the '/cgi-bin/portal.cgi' endpoint. The payload must include the 'action' field set to 'register_email', the 'page' field set to 'register_email_wizard', and the 'id_email_check_btn' field containing the crafted command injection payload, such as a command to list directory contents or create a file in the '/tmp' directory.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.