vendor:
RE6500
by:
RE-Solver
7.8
CVSS
HIGH
Unauthenticated RCE
20
CWE
Product Name: RE6500
Affected Version From: FW V1.05
Affected Version To: FW v1.0.11.001
Patch Exists: YES
Related CWE: N/A
CPE: h:linksys:re6500
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: FW V1.05 up to FW v1.0.11.001
2020
Linksys RE6500 1.0.11.001 – Unauthenticated RCE
An attacker can access system OS configurations and commands that are not intended for use beyond the web UI through unsanitized user input in the web interface for Linksys WiFi extender RE6500.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the web interface.