Vulnerabilities > Linksys

DATE CVE VULNERABILITY TITLE RISK
2020-12-26 CVE-2020-35714 OS Command Injection vulnerability in Linksys Re6500 Firmware
Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program.
network
low complexity
linksys CWE-78
8.8
2020-12-26 CVE-2020-35713 OS Command Injection vulnerability in Linksys Re6500 Firmware
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.
network
low complexity
linksys CWE-78
critical
9.8
2020-02-12 CVE-2009-5140 Improper Restriction of Excessive Authentication Attempts vulnerability in Linksys Spa2102 Firmware
The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.
network
low complexity
linksys CWE-307
8.8
2020-02-07 CVE-2013-3067 Cross-site Scripting vulnerability in Linksys Wrt310N Firmware 2.0.0.1
Linksys WRT310Nv2 2.0.0.1 is vulnerable to XSS.
network
low complexity
linksys CWE-79
5.4
2019-11-21 CVE-2019-16340 Forced Browsing vulnerability in Linksys products
Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.
network
low complexity
linksys CWE-425
critical
9.8
2019-10-25 CVE-2013-4658 Path Traversal vulnerability in Linksys Ea6500 Firmware
Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share.
network
low complexity
linksys CWE-22
critical
9.8
2019-07-17 CVE-2019-11535 Command Injection vulnerability in Linksys Re6300 Firmware and Re6400 Firmware
Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execution.
network
low complexity
linksys CWE-77
critical
9.8
2019-06-17 CVE-2019-7579 Improper Authentication vulnerability in Linksys Wrt1900Acs Firmware 1.0.3.187766
An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices.
network
low complexity
linksys CWE-287
7.5
2019-06-11 CVE-2009-5157 Command Injection vulnerability in Linksys Wag54G2 Firmware 1.00.10
On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c4_ping_ipaddr variable.
network
low complexity
linksys CWE-77
8.8
2019-06-06 CVE-2019-7311 Missing Encryption of Sensitive Data vulnerability in Linksys Wrt1900Acs Firmware 1.0.3.187766
An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices.
local
low complexity
linksys CWE-311
7.8