CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Oracle WebLogic Server Core Component Unauthorized Remote Takeover Vulnerability
A vulnerability exists in Oracle WebLogic Server within the Oracle Fusion Middleware suite, specifically in the Core component. This issue affects version 12.2.1.4.0 and 14.1.1.0.0. The vulnerability allows an unauthenticated attacker with network access via T3 or IIOP to compromise the WebLogic Server. Exploitation of this vulnerability can lead to a complete takeover of the server.
Oracle MySQL Server Performance Schema Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Server component of Oracle MySQL. This issue affects versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior. The vulnerability allows a high-privileged attacker with network access to MySQL Server via multiple protocols to cause a hang or a frequently repeatable crash, leading to a complete denial-of-service condition on the server.
Oracle VM VirtualBox Core Component Vulnerability Allowing Unauthorized Data Access
A vulnerability exists in the Oracle VM VirtualBox product, specifically in the Core component, affecting versions prior to 7.0.24 and prior to 7.1.6. This easily exploitable vulnerability allows a low-privileged attacker with access to the infrastructure where Oracle VM VirtualBox runs to compromise the application. Successful exploitation can lead to unauthorized access to critical data or complete access to all data accessible through Oracle VM VirtualBox.
Oracle Analytics Desktop Vulnerability Allowing Takeover on Affected Versions Prior to 8.1.0
A vulnerability exists in the Install component of Oracle Analytics Desktop, specifically in versions prior to 8.1.0. This easily exploitable issue allows a low-privileged attacker with access to the environment where Oracle Analytics Desktop runs to compromise the application. Successful exploitation can lead to a complete takeover of Oracle Analytics Desktop.
Oracle MySQL InnoDB Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the InnoDB component. This issue affects supported versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable by a high-privileged attacker with network access through multiple protocols, allowing them to compromise the MySQL Server. Successful exploitation can lead to an unauthorized ability to cause the server to hang or crash frequently, resulting in a complete denial-of-service condition.
Oracle PeopleSoft Enterprise PeopleTools Panel Processor Vulnerability Allowing Unauthorized Data Access
A vulnerability has been identified in the PeopleSoft Enterprise PeopleTools product, specifically within the Panel Processor component. This issue affects versions 8.60 and 8.61. The vulnerability is easily exploitable, allowing a low-privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful exploitation of this vulnerability could lead to unauthorized read access to certain data within PeopleSoft Enterprise PeopleTools.
Oracle MySQL Server Denial-of-Service Vulnerability in Information Schema Component
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Server: Information Schema component. This issue affects MySQL versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable by a high-privileged attacker with network access through multiple protocols, allowing them to cause a hang or a frequently repeatable crash of the MySQL Server.
Oracle Primavera P6 EPPM Web Access Unauthenticated Data Modification Vulnerability
An easily exploitable vulnerability has been identified in the Web Access component of Oracle Primavera P6 Enterprise Project Portfolio Management. This vulnerability affects versions 20.12.1.0 through 20.12.21.5, 21.12.1.0 through 21.12.20.0, 22.12.1.0 through 22.12.16.0, and 23.12.1.0 through 23.12.10.0. The issue allows an unauthenticated attacker with network access via HTTP to compromise Primavera P6 EPPM. Exploitation of this vulnerability requires human interaction from a third party. Successful attacks can lead to unauthorized update, insert, or delete access to some of the data accessible in Primavera P6 EPPM.
Oracle JD Edwards EnterpriseOne Tools Design Tools Security Vulnerability Allowing Unauthorized Data Access
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically within the Design Tools component, for versions prior to 9.2.9.0. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the affected tools. Exploitation of this vulnerability requires human interaction from a person other than the attacker. While the issue is contained within JD Edwards EnterpriseOne Tools, successful attacks could significantly impact additional products, leading to a scope change. The vulnerability allows unauthorized update, insert, or delete access to some accessible data within JD Edwards EnterpriseOne Tools, as well as unauthorized read access to a subset of that data.
Oracle Primavera P6 EPPM Web Access Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability has been identified in the Web Access component of Oracle Primavera P6 Enterprise Project Portfolio Management, affecting versions 20.12.1.0 through 20.12.21.5, 21.12.1.0 through 21.12.20.0, 22.12.1.0 through 22.12.16.0, and 23.12.1.0 through 23.12.10.0. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Primavera P6 EPPM. Exploitation requires human interaction from a third party. While the vulnerability resides within Primavera P6 EPPM, successful attacks could significantly impact other products, leading to a scope change. Exploiting this vulnerability could result in unauthorized read, update, insert, or delete access to certain accessible data within Primavera P6 EPPM.
Oracle MySQL Server Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Oracle MySQL Server versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior. This vulnerability allows a high-privileged attacker with network access to MySQL Server via multiple protocols to cause a hang or a frequently repeatable crash, leading to a complete denial-of-service condition on the MySQL Server.
Oracle JD Edwards EnterpriseOne Tools Monitoring and Diagnostics SEC Unauthenticated Takeover Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Monitoring and Diagnostics SEC component, prior to version 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to a complete takeover of the application.
Oracle MySQL InnoDB Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically within the InnoDB component. This issue affects supported versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable by a high-privileged attacker with network access through multiple protocols, allowing them to cause a hang or a frequently repeatable crash of the MySQL Server.
Oracle MySQL Server Denial-of-Service Vulnerability in the Parser Component
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Parser component. This issue affects MySQL Server versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable, allowing a low-privileged attacker with network access via multiple protocols to disrupt MySQL Server operations. Successful exploitation can lead to unauthorized actions causing the server to hang or crash frequently, resulting in a complete denial-of-service condition.
Oracle MySQL Server Thread Pooling Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Server: Thread Pooling component. This vulnerability affects MySQL Server versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior. The issue is easily exploitable, allowing an unauthenticated attacker with network access via multiple protocols to compromise the MySQL Server. Successful exploitation can lead to unauthorized actions causing the server to hang or crash frequently, resulting in a complete denial-of-service condition.
Oracle MySQL Server Vulnerability Allowing Unauthorized Data Access
A vulnerability exists in Oracle MySQL Server in versions through 8.0.40, 8.4.3 and 9.1.0. This difficult-to-exploit vulnerability allows a high-privileged attacker with access to the MySQL Server environment to compromise the server. Exploitation requires human interaction from a third party. Successful attacks could lead to unauthorized read access to certain data within MySQL Server.
Oracle MySQL Server Denial-of-Service Vulnerability in Privileges Component
A denial-of-service vulnerability has been identified in Oracle MySQL Server, specifically in the Privileges component of the Security feature. This issue affects MySQL versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is difficult to exploit but allows a high-privileged attacker with network access through multiple protocols to disrupt MySQL Server operations. Successful exploitation can lead to a complete hang or a frequently repeatable crash of the MySQL Server.
Oracle MySQL Server Denial-of-Service Vulnerability in Optimizer Component
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Optimizer component. This issue affects MySQL Server versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable by a low-privileged attacker with network access through multiple protocols, allowing them to cause a hang or a frequently repeatable crash of the MySQL Server, leading to a complete denial-of-service condition.
Oracle JD Edwards EnterpriseOne Tools Web Runtime SEC Vulnerability Allowing Unauthorized Data Modification
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized update, insert, or delete access to some data within JD Edwards EnterpriseOne Tools.
Oracle E-Business Suite Customer Care Service Requests Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability exists in the Oracle Customer Care component of Oracle E-Business Suite, specifically in versions 12.2.5 through 12.2.13. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Customer Care. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all data accessible within Oracle Customer Care.
Oracle JD Edwards EnterpriseOne Tools Web Runtime SEC Vulnerability Allowing Unauthorized Takeover
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized takeover of the application.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Exposure Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized read access to certain JD Edwards EnterpriseOne Tools data.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Access Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, prior to version 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation requires human interaction from a third party. While the vulnerability is contained within JD Edwards EnterpriseOne Tools, its effects may extend to other products, leading to a scope change. Exploitation of this vulnerability could result in unauthorized access to read, update, insert, or delete certain data within JD Edwards EnterpriseOne Tools.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Access Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation requires human interaction from a third party. While the vulnerability is contained within JD Edwards EnterpriseOne Tools, it may significantly impact additional products. Exploitation of this vulnerability could lead to unauthorized read access to certain JD Edwards EnterpriseOne Tools data, as well as unauthorized update, insert, or delete access to other accessible data.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Access Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, prior to version 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized access to critical data or complete access to all data within JD Edwards EnterpriseOne Tools.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Access Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized access to critical data or complete access to all data within JD Edwards EnterpriseOne Tools.
Oracle JD Edwards Web Runtime SEC Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the JD Edwards EnterpriseOne Tools product, specifically within the Web Runtime SEC component. This issue affects versions prior to 9.2.9.0. The vulnerability is easily exploitable, allowing a low-privileged attacker with network access via HTTP to disrupt JD Edwards EnterpriseOne Tools. Successful exploitation can lead to a complete hang or a frequently repeatable crash of the application.
Oracle JD Edwards Web Runtime SEC Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the JD Edwards EnterpriseOne Tools product, specifically within the Web Runtime SEC component. This issue affects versions prior to 9.2.9.0. The vulnerability is easily exploitable, allowing a low-privileged attacker with network access via HTTP to disrupt JD Edwards EnterpriseOne Tools. Successful exploitation can lead to a complete hang or a frequently repeatable crash of the application.
Oracle JD Edwards Web Runtime SEC Vulnerability in EnterpriseOne Tools Allowing Data Access and Modification
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically within the Web Runtime SEC component. This issue affects versions prior to 9.2.9.0. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Exploitation of this vulnerability requires human interaction from someone other than the attacker. While the vulnerability is contained within JD Edwards EnterpriseOne Tools, successful attacks could significantly impact additional products, leading to a scope change. Exploitation of this vulnerability could result in unauthorized read access to certain subsets of JD Edwards EnterpriseOne Tools data, as well as unauthorized update, insert, or delete access to other accessible data within the same tools.
Oracle E-Business Suite Project Foundation Technology Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability exists in the Oracle Project Foundation component of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.13. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Project Foundation. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete access to all data accessible within Oracle Project Foundation.
Oracle MySQL Server Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Oracle MySQL Server versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. This vulnerability allows a high-privileged attacker with network access to MySQL Server, through multiple protocols, to cause a hang or a frequently repeatable crash, leading to a complete denial-of-service condition on the server.
Oracle MySQL Server Denial-of-Service Vulnerability in Optimizer Component
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Optimizer component. This issue affects MySQL Server versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior. The vulnerability is easily exploitable by a high-privileged attacker with network access through multiple protocols, allowing them to cause a hang or a frequently repeatable crash of the MySQL Server, leading to a complete denial-of-service condition.
Oracle MySQL InnoDB Component Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the InnoDB component. This vulnerability affects supported versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. It allows a high-privileged attacker with network access to MySQL Server via multiple protocols to cause a hang or a frequently repeatable crash, leading to a complete denial-of-service condition on the server.
Oracle Java SE and GraalVM Vulnerability Allowing Unauthorized Data Access
A vulnerability has been identified in multiple versions of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. This vulnerability, which affects the Hotspot component, allows an unauthenticated attacker with network access to compromise the Java runtime. Successful exploitation can lead to unauthorized read access and the ability to update, insert, or delete certain accessible data. The vulnerability can be exploited through APIs, potentially via a web service, and also impacts Java deployments that run untrusted code from the internet, relying on the Java sandbox for security.
Oracle MySQL Server Denial-of-Service Vulnerability in Optimizer Component
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Optimizer component. This issue affects MySQL Server versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable by a low-privileged attacker with network access through multiple protocols, allowing them to cause a hang or a frequently repeatable crash of the MySQL Server.
Oracle MySQL Server Denial-of-Service Vulnerability in Optimizer Component
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Optimizer component. This issue affects MySQL Server versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable, allowing a low-privileged attacker with network access via multiple protocols to disrupt MySQL Server operations. Successful exploitation can lead to unauthorized actions causing the server to hang or crash frequently, resulting in a complete denial-of-service condition.
Oracle MySQL Server Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Oracle MySQL Server versions through 8.4.3 and 9.1.0. This vulnerability allows a high-privileged attacker with network access to MySQL Server, via multiple protocols, to cause a hang or a frequently repeatable crash, leading to a complete denial-of-service condition on the server.
Oracle HTTP Server Core Component Vulnerability in Oracle Fusion Middleware
A vulnerability has been identified in the Oracle HTTP Server component of Oracle Fusion Middleware, specifically in version 12.2.1.4.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the server. Successful exploitation can lead to unauthorized read access to certain data accessible through Oracle HTTP Server.
Oracle MySQL InnoDB Component Denial-of-Service and Data Manipulation Vulnerability
A vulnerability exists in the MySQL Server product of Oracle MySQL, specifically in the InnoDB component. Affected versions include 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. This vulnerability is easily exploitable and allows a high-privileged attacker with network access via multiple protocols to compromise the MySQL Server. Successful exploitation can lead to an unauthorized ability to cause a hang or a frequently repeatable crash, resulting in a complete denial-of-service for the MySQL Server. Additionally, it allows unauthorized update, insert, or delete access to some data accessible by the MySQL Server.
Oracle MySQL Enterprise Firewall Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Enterprise Firewall component of Oracle MySQL. This issue affects versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is difficult to exploit but allows a high-privileged attacker with network access via multiple protocols to disrupt MySQL Enterprise Firewall. Successful exploitation can lead to a complete hang or a frequently repeatable crash of the firewall component.
Oracle MySQL Server Denial-of-Service Vulnerability in Privileges Component
A denial-of-service vulnerability has been identified in Oracle MySQL Server, specifically in the Privileges component of the Security feature. This issue affects MySQL Server versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior. The vulnerability is difficult to exploit but allows a high-privileged attacker with access to the MySQL Server environment to cause a complete server hang or a frequently repeatable crash, leading to a total denial-of-service condition.
Oracle MySQL Server Privilege Vulnerability Leading to Denial-of-Service
A vulnerability exists in Oracle MySQL Server in versions 8.4.3 and prior, as well as 9.1.0 and prior. This vulnerability, which is difficult to exploit, allows a high-privileged attacker with network access through multiple protocols to compromise the MySQL Server. Successful exploitation can lead to an unauthorized ability to cause the server to hang or crash frequently, resulting in a complete denial-of-service condition.
Oracle MySQL Server Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Oracle MySQL Server, specifically in the optimizer component. This issue affects MySQL Server versions through 8.0.36 and through 8.4.0. The vulnerability allows a high-privileged attacker with network access via multiple protocols to compromise the MySQL Server. Exploitation of this vulnerability can lead to unauthorized actions causing the MySQL Server to hang or crash repeatedly, resulting in a complete denial-of-service.
Oracle MySQL InnoDB Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically within the InnoDB component. This issue affects supported versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable by a high-privileged attacker with network access through multiple protocols, allowing them to cause a hang or a frequently repeatable crash of the MySQL Server.
Oracle MySQL InnoDB Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the InnoDB component of Oracle MySQL Server. This issue affects MySQL versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability allows a high-privileged attacker with network access to MySQL Server via multiple protocols to cause a complete server hang or a frequently repeatable crash, leading to a total denial-of-service condition.
Oracle E-Business Suite Advanced Outbound Telephony Region Mapping Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability exists in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite, specifically in versions 12.2.3 through 12.2.10. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Exploitation of this vulnerability requires human interaction from a third party. While the vulnerability is contained within Oracle Advanced Outbound Telephony, successful attacks could significantly affect other products, leading to a scope change. The vulnerability allows for unauthorized read access to certain subsets of Oracle Advanced Outbound Telephony data, as well as unauthorized update, insert, or delete access to some accessible data within the application.
Linksys E8450 Buffer Overflow Vulnerability in DHCP Field Parsing
A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The issue arises because the parsed field 'hidden_dhcp_num' is copied to the stack without proper length verification, creating the potential for memory corruption.
Linksys E8450 Buffer Overflow Vulnerability in LAN IP Address Parsing
A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The issue arises because the parsed field 'lan_ipaddr' is copied to the stack without proper length verification, creating the potential for memory corruption.
Linksys E8450 Buffer Overflow Vulnerability in DHCP Start IP Parsing
A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The issue arises in the JSON parsing function 'sub_422eb8', where the 'dhcpstart_ip' field is copied to the stack using 'strcpy' without proper length validation. This lack of verification creates an opportunity for a buffer overflow, potentially allowing for arbitrary code execution or causing the device to crash.
Linksys E8450 Command Injection Vulnerability
A command injection vulnerability has been identified in the Linksys E8450 router, specifically in firmware version 1.2.00.360516. The issue arises in the 'id_email_check_btn' field, where user-supplied input is improperly sanitized before being passed to the system function, allowing for arbitrary command execution.
