Linksys RE6500
cpe:2.3:o:linksys:re6500_firmware:*:*:*:*:*:*:*
- 1.0.013.001
- 1.0.04.001
- 1.0.04.002
- 1.1.05.003
- 1.2.07.001
A critical OS command injection vulnerability has been identified in Linksys RE6500, RE6250, RE6300, RE6350, RE7000, and RE9000 routers, all running specific firmware versions. The vulnerability arises in the 'RP_pingGatewayByBBS' function within the '/goform/RP_pingGatewayByBBS' file. It allows remote attackers to inject malicious commands by manipulating the 'ip', 'nm', and 'gw' arguments.
Exploitation of this vulnerability allows for OS command injection, where an attacker can execute arbitrary commands on the device's operating system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.