Linksys E8450
cpe:2.3:h:linksys:e8450:*:*:*:*:*:*:*, +1 more
- <= 1.2.00.360516
A critical buffer overflow vulnerability has been identified in the Linksys E8450 router, affecting versions through 1.2.00.360516. The issue arises in the HTTP POST request handler, specifically within the 'portal.cgi' file and the 'set_device_language' function. The vulnerability can be exploited remotely by manipulating the 'dut_language' argument, leading to a buffer overflow that could allow an attacker to control the return address and execute arbitrary commands.
Exploitation of this vulnerability causes a buffer overflow, which can be used to control the return address and execute arbitrary commands on the device.
To reproduce this vulnerability, send a malicious HTTP POST request to the router's 'portal.cgi' file. Include crafted JSON data that manipulates the 'dut_language' argument to trigger the buffer overflow.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.