Linksys RE6500
cpe:2.3:o:linksys:re6500_firmware:*:*:*:*:*:*:*
- 1.0.013.001
- 1.0.04.001
- 1.2.07.001
- 1.1.05.003
- 1.0.04.002
A command injection vulnerability has been identified in Linksys routers RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000, all running specific firmware versions. This vulnerability allows remote attackers to execute arbitrary operating system commands by manipulating the 'filename' argument in the 'cgiMain' function of the 'upload.cgi' file. The issue has been publicly disclosed and is actively exploitable.
Exploitation of this vulnerability allows for remote command execution on the affected device.
To reproduce this vulnerability, send a POST request to '/cgi-bin/upload.cgi' with the 'filename' parameter crafted to include a command, such as one that would initiate a reverse shell. The router will execute the command, providing a shell access.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.