Vulnerabilities > Linksys > High

DATE CVE VULNERABILITY TITLE RISK
2022-09-12 CVE-2022-35572 Missing Authentication for Critical Function vulnerability in Linksys E5350 Firmware 1.0.00.037
On Linksys E5350 WiFi Router with firmware version 1.0.00.037 and lower, (and potentially other vendors/devices due to code reuse), the /SysInfo.htm URI does not require a session ID.
network
low complexity
linksys CWE-306
7.5
2022-08-24 CVE-2022-38132 OS Command Injection vulnerability in Linksys Mr8300 Firmware 1.0
Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service.
local
low complexity
linksys CWE-78
8.8
2020-12-26 CVE-2020-35716 Unspecified vulnerability in Linksys Re6500 Firmware
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segmentation fault) via a long /goform/langSwitch langSelectionOnly parameter.
network
low complexity
linksys
7.5
2020-12-26 CVE-2020-35715 OS Command Injection vulnerability in Linksys Re6500 Firmware
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shell metacharacters in a filename to the upload_settings.cgi page.
network
low complexity
linksys CWE-78
8.8
2020-12-26 CVE-2020-35714 OS Command Injection vulnerability in Linksys Re6500 Firmware
Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program.
network
low complexity
linksys CWE-78
8.8
2020-02-12 CVE-2009-5140 Improper Restriction of Excessive Authentication Attempts vulnerability in Linksys Spa2102 Firmware
The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.
network
low complexity
linksys CWE-307
8.8
2019-06-17 CVE-2019-7579 Improper Authentication vulnerability in Linksys Wrt1900Acs Firmware 1.0.3.187766
An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices.
network
low complexity
linksys CWE-287
7.5
2019-06-11 CVE-2009-5157 Command Injection vulnerability in Linksys Wag54G2 Firmware 1.00.10
On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c4_ping_ipaddr variable.
network
low complexity
linksys CWE-77
8.8
2019-06-06 CVE-2019-7311 Missing Encryption of Sensitive Data vulnerability in Linksys Wrt1900Acs Firmware 1.0.3.187766
An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices.
local
low complexity
linksys CWE-311
7.8
2018-10-17 CVE-2018-3955 OS Command Injection vulnerability in Linksys E1200 Firmware and E2500 Firmware
An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04).
network
low complexity
linksys CWE-78
7.2