The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui_language POST parameter to the apply.cgi form endpoint. This occurs in do_upgrade_post in mini_httpd. NOTE: This vulnerability only affects products that are no longer supported by the maintaine
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HBelkin Linksys Wrt160nl
HWBelkinall versionsBelkin Linksys Wrt160nl Firmware
OSBelkin1.0.04.002_us_20130619
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Command Injection
Related vulnerabilities
CVE-2023-27217CRITICAL9.8PL ✓same vendor
Stack-based buffer overflow w Belkin Smart Outlet V2 F7C063 via UPnP
CVE-2022-30105CRITICAL9.8PL ✓same vendor
Belkin N300 Firmware — zdalne command injection z uprawnieniami root
CVE-2013-7173CRITICAL9.8PL ✓same vendor
Buffer overflow w routerach Belkin N750
CVE-2013-3091CRITICAL9.8PL ✓same vendor
Belkin N300 — Authentication Bypass via Javascript Debugging
CVE-2013-2748CRITICAL9.8PL ✓same vendor
Belkin Wemo Switch — nieautoryzowane przesyłanie plików na urządzenie