CVE-2019-11535

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
17/07/2019
Last modified:
24/08/2020

Description

Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execution. An attacker can access system OS configurations and commands that are not intended for use beyond the web UI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linksys:re6400_firmware:*:*:*:*:*:*:*:* 1.2.04.022 (including)
cpe:2.3:h:linksys:re6400:1:*:*:*:*:*:*:*
cpe:2.3:o:linksys:re6300_firmware:*:*:*:*:*:*:*:* 1.2.04.022 (including)
cpe:2.3:h:linksys:re6300:1:*:*:*:*:*:*:*