Vulnerability index

Browse CVEs

198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

E2000 Firmware HIGH 8.8
CVE-2024-27497EPSS 27%

Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.

No fix yet
Fix from $1,950 2024-03-01
E1700 Firmware HIGH 8.0
CVE-2024-22544EPSS 9%

An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTim…

No fix yet
Fix from $1,950 2024-02-27
E1700 Firmware MEDIUM 6.1
CVE-2024-22543

An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to …

No fix yet
Fix from $1,600 2024-02-27
Wrt54gl Firmware HIGH 7.5
CVE-2024-1404

A vulnerability was found in Linksys WRT54GL 4.30.18 and classified as problematic. Affected by this issue is some unknown functionality of the file …

Mitigation only
Fix from $1,950 2024-02-09
E2000 Firmware HIGH 7.2
CVE-2023-31740

There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, …

No fix yet
Fix from $1,950 2023-05-23
E2000 Firmware HIGH 7.2
CVE-2023-31741

There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, …

No fix yet
Fix from $1,950 2023-05-23
Wrt54gl Firmware HIGH 7.2
CVE-2023-31742EPSS 9%

There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privi…

No fix yet
Fix from $1,950 2023-05-22
E8450 Firmware HIGH 8.8
CVE-2022-38841EPSS 11%

Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.

No fix yet
Fix from $1,950 2023-04-16
Wrt54gl Firmware HIGH 7.5
CVE-2022-43972

A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereferen…

Fix: after 4.30.18.006
Fix from $1,950 2023-01-09
Wrt54gl Firmware HIGH 7.2
CVE-2022-43970EPSS 19%

A buffer overflow vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A stack-based buffer overflow in …

Fix: after 4.30.18.006
Fix from $1,950 2023-01-09
Wumc710 Firmware HIGH 7.2
CVE-2022-43971

An arbitrary code exection vulnerability exists in Linksys WUMC710 Wireless-AC Universal Media Connector with firmware <= 1.0.02 (build3). The do_set…

Fix: 1.0.02+
Fix from $1,950 2023-01-09
Wrt54gl Firmware HIGH 7.2
CVE-2022-43973

An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI functio…

Fix: after 4.30.18.006
Fix from $1,950 2023-01-09
E5350 Firmware HIGH 7.5
CVE-2022-35572

On Linksys E5350 WiFi Router with firmware version 1.0.00.037 and lower, (and potentially other vendors/devices due to code reuse), the /SysInfo.htm …

Fix: after 1.0.00.037
Fix from $1,950 2022-09-12
E1200 Firmware CRITICAL 9.8
CVE-2022-38555EPSS 9%

Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.

Mitigation only
Fix from $2,300 2022-08-28
Mr8300 Firmware HIGH 8.8
CVE-2022-38132

Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and password, an attacker connect…

Mitigation only
Fix from $1,950 2022-08-24
Re6500 Firmware CRITICAL 9.8
CVE-2020-35713EPSS 33%

Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters …

Fix: 1.0.012.001+
Fix from $2,300 2020-12-26
Re6500 Firmware HIGH 8.8
CVE-2020-35714

Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in c…

Fix: 1.0.011.001+
Fix from $1,950 2020-12-26
Re6500 Firmware HIGH 8.8
CVE-2020-35715

Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shell metacharacters in a filenam…

Fix: 1.0.012.001+
Fix from $1,950 2020-12-26
Re6500 Firmware HIGH 7.5
CVE-2020-35716

Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segmentation fault) via a long /gofo…

Fix: 1.0.012.001+
Fix from $1,950 2020-12-26
Spa2102 Firmware HIGH 8.8
CVE-2009-5140

The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which m…

Mitigation only
Fix from $1,950 2020-02-12
Wrt310n Firmware MEDIUM 5.4
CVE-2013-3067

Linksys WRT310Nv2 2.0.0.1 is vulnerable to XSS.

No fix yet
Fix from $1,600 2020-02-07
Velop Whw0303 Firmware CRITICAL 9.8
CVE-2019-16340EPSS 19%

Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.

Patch available
Fix from $2,300 2019-11-21
Ea6500 Firmware CRITICAL 9.8
CVE-2013-4658EPSS 9%

Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share.

No fix yet
Fix from $2,300 2019-10-25
Re6400 Firmware CRITICAL 9.8
CVE-2019-11535EPSS 5%

Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execu…

Fix: after 1.2.04.022
Fix from $2,300 2019-07-17
Wrt1900acs Firmware HIGH 7.5
CVE-2019-7579

An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. An ability exists for an unauthenticated user to browse a confidential ui/1.0.99.…

No fix yet
Fix from $1,950 2019-06-17
Wag54g2 Firmware HIGH 8.8
CVE-2009-5157EPSS 6%

On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c4_ping_ipaddr variable.

No fix yet
Fix from $1,950 2019-06-11
Wrt1900acs Firmware HIGH 7.8
CVE-2019-7311

An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. A lack of encryption in how the user login cookie (admin-auth) is stored on a vic…

Mitigation only
Fix from $1,950 2019-06-06
E1200 Firmware HIGH 7.2
CVE-2018-3953EPSS 14%

Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to O…

No fix yet
Fix from $1,950 2018-10-17
E1200 Firmware HIGH 7.2
CVE-2018-3954

Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to O…

No fix yet
Fix from $1,950 2018-10-17
E1200 Firmware HIGH 7.2
CVE-2018-3955

An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2…

No fix yet
Fix from $1,950 2018-10-17