Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.
References
Configurations
Configuration 1 (hide)
AND |
|
History
17 Jun 2025, 20:50
Type | Values Removed | Values Added |
---|---|---|
First Time |
Linksys re7000
Linksys Linksys re7000 Firmware |
|
CPE | cpe:2.3:o:linksys:re7000_firmware:2.0.15:*:*:*:*:*:*:* cpe:2.3:o:linksys:re7000_firmware:2.0.11:*:*:*:*:*:*:* cpe:2.3:o:linksys:re7000_firmware:2.0.9:*:*:*:*:*:*:* cpe:2.3:h:linksys:re7000:-:*:*:*:*:*:*:* |
|
References | () https://github.com/ZackSecurity/VulnerReport/blob/cve/Linksys/1.md - Exploit | |
References | () https://immense-mirror-b42.notion.site/Linksys-RE7000-command-injection-vulnerability-c1a47abf5e8d4dd0934d20d77da930bd - Broken Link |
21 Nov 2024, 09:01
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/ZackSecurity/VulnerReport/blob/cve/Linksys/1.md - | |
References | () https://immense-mirror-b42.notion.site/Linksys-RE7000-command-injection-vulnerability-c1a47abf5e8d4dd0934d20d77da930bd - |
14 Aug 2024, 20:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-284 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
12 Apr 2024, 12:43
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
11 Apr 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-11 21:15
Updated : 2025-06-17 20:50
NVD link : CVE-2024-25852
Mitre link : CVE-2024-25852
CVE.ORG link : CVE-2024-25852
JSON object : View
Products Affected
linksys
- re7000
- re7000_firmware
CWE
CWE-284
Improper Access Control