RULE(RULE ID:338043)

Rule General Information
Release Date: 2024-05-28
Rule Name: Linksys RE7000 Command Injection Vulnerability (CVE-2024-25852)
Severity:
CVE ID:
Rule Protection Details
Description: Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://github.com/ZackSecurity/VulnerReport/blob/cve/Linksys/1.md
https://immense-mirror-b42.notion.site/Linksys-RE7000-command-injection-vulnerability-c1a47abf5e8d4dd0934d20d77da930bd
Solutions
Please contact the software vendor to update the software patch.