Linksys RE6500
cpe:2.3:o:linksys:re6500_firmware:*:*:*:*:*:*:*
- 1.0.013.001
- 1.0.04.001
- 1.2.07.001
- 1.1.05.003
- 1.0.04.002
A command injection vulnerability has been identified in Linksys router models RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000, all running specific firmware versions. The vulnerability resides in the addStaticRoute function of the /goform/addStaticRoute file, where several static route parameters can be manipulated to inject and execute arbitrary operating system commands. This issue can be exploited remotely, and a public proof-of-concept exploit is available.
Exploitation of this vulnerability allows for arbitrary operating system command execution on the affected router.
To reproduce this vulnerability, send a POST request to the /goform/addStaticRoute endpoint with the staticRoute_IP_setting, staticRoute_Netmask_setting, staticRoute_Gateway_setting, staticRoute_Metric_setting, and staticRoute_destType_setting parameters. The staticRoute_destType_setting parameter should be crafted to include the desired command, such as launching a reverse shell via telnet.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.