Vulnerabilities > Linksys > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-07-17 CVE-2019-11535 Command Injection vulnerability in Linksys Re6300 Firmware and Re6400 Firmware
Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execution.
network
low complexity
linksys CWE-77
critical
9.8
2017-12-21 CVE-2017-17411 OS Command Injection vulnerability in Linksys Wvbr0 Firmware
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0.
network
low complexity
linksys CWE-78
critical
9.8
2010-06-10 CVE-2010-1573 Use of Hard-coded Credentials vulnerability in Linksys Wap54G Firmware
Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the (1) data1, (2) data2, or (3) data3 parameters to (a) Debug_command_page.asp and (b) debug.cgi.
network
low complexity
linksys CWE-798
critical
9.8