Linksys WVBR0-25 CVE-2017-17411 Remote Command Injection Vulnerability

Linksys WVBR0-25 is prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.

Successful exploit allows an attacker to execute arbitrary commands with user privileges in context of the affected device.

Linksys WVBR0-25 is vulnerable; other versions may also be affected.


Bugtraq ID: 102212
Class: Input Validation Error
CVE: CVE-2017-17411

Remote: Yes
Local: No
Published: Dec 18 2017 12:00AM
Updated: Dec 18 2017 12:00AM
Credit: Ricky "HeadlessZeke" Lawshae
Vulnerable: Linksys WVBR0 25

Not Vulnerable:


The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.

Related Posts