Linksys E-Series Routers Multiple Vulnerabilities
Last Update Date:
25 Feb 2014 09:32
Release Date:
25 Feb 2014
3950
Views
RISK: High Risk
TYPE: Operating Systems - Networks OS
Multiple vulnerabilities have been identified in multiple Linksys E-Series routers, which can be exploited by malicious people to bypass certain security restrictions.
- The device does not properly restrict access to tmUnblock.cgi and hndUnblock.cgi, which can be exploited to inject and execute arbitrary shell commands.
Note: Reportedly, this vulnerability is currently actively exploited in the wild. - The device does not properly restrict access to the access console, which can be exploited to gain access to otherwise restricted functionality via TCP port 8083.
Note: Vendor patch is currently unavailable.
Impact
- Security Restriction Bypass
System / Technologies affected
- Linksys E4200
- Linksys EA2700
- Linksys EA3500
- Linksys EA4500
Solutions
- Note: Vendor patch is currently unavailable.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with