Vulnerabilities > Linksys > Velop Firmware > 1.1.2.187020

DATE CVE VULNERABILITY TITLE RISK
2018-09-19 CVE-2018-17208 OS Command Injection vulnerability in Linksys Velop Firmware 1.1.2.187020
Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts that can be discovered with binwalk on the firmware, but are not visible in the web interface).
network
linksys CWE-78
critical
9.3