Vulnerability index

Browse CVEs

198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Velop Firmware HIGH 8.8
CVE-2018-17208

Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cg…

No fix yet
Fix from $1,950 2018-09-19
Wvbr0 Firmware CRITICAL 9.8
CVE-2017-17411EPSS 88%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to …

Fix: 1.0.41+
Fix from $2,300 2017-12-21
Ea4500 Firmware HIGH 8.8
CVE-2017-10677

Cross-Site Request Forgery (CSRF) exists on Linksys EA4500 devices with Firmware Version before 2.1.41.164606, as demonstrated by a request to apply.…

Fix: after 2.0.36
Fix from $1,950 2017-08-06
Ea3500 Firmware HIGH 7.5
CVE-2014-8244

Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6…

Fix: after 2.0.14294
Fix from $1,950 2014-11-01
Ea6500 Firmware HIGH 7.1
CVE-2013-3066

Linksys EA6500 with firmware 1.1.28.147876 does not properly restrict access, which allows remote attackers to obtain sensitive information (clients …

No fix yet
Fix from $1,950 2014-09-29
Ea6500 Firmware MEDIUM 6.8
CVE-2013-3064

Open redirect vulnerability in ui/dynamic/unsecured.html in Linksys EA6500 with firmware 1.1.28.147876 allows remote attackers to redirect users to a…

No fix yet
Fix from $1,600 2014-09-29
Wap54gv3 HIGH 10.0
CVE-2010-2261

Linksys WAP54Gv3 firmware 3.04.03 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) data2 and (2)…

Fix: after 3.04.03
Fix from $1,950 2010-06-10
Wap54g Firmware CRITICAL 9.8
CVE-2010-1573EPSS 21%

Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web page…

Fix: after 3.04.03
Fix from $2,300 2010-06-10
Wrt54gl HIGH 10.0
CVE-2009-3341

Buffer overflow on the Linksys WRT54GL wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by …

No fix yet
Fix from $1,950 2009-09-24
Wap400n HIGH 10.0
CVE-2008-4594

Unspecified vulnerability in the SNMPv3 component in Linksys WAP4400N firmware 1.2.14 on the Marvell Semiconductor 88W8361P-BEM1 chipset has unknown …

No fix yet
Fix from $1,950 2008-10-17
Wap400n HIGH 7.1
CVE-2008-4441

The Marvell driver for the Linksys WAP4400N Wi-Fi access point with firmware 1.2.14 on the Marvell 88W8361P-BEM1 chipset, when WEP mode is enabled, d…

Mitigation only
Fix from $1,950 2008-10-14
Spa 2102 Phone Adapter HIGH 7.8
CVE-2008-2092

Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: the…

No fix yet
Fix from $1,950 2008-05-06
Wag54gs HIGH 7.5
CVE-2007-6709

The Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware has "admin" as its default password for the "admin" account, whic…

No fix yet
Fix from $1,950 2008-03-13
Wrt54g HIGH 10.0
CVE-2008-1247EPSS 5%

The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts, which allows remote attackers…

No fix yet
Fix from $1,950 2008-03-10
Wrt54g HIGH 10.0
CVE-2008-1268

The FTP server on the Linksys WRT54G 7 router with 7.00.1 firmware does not verify authentication credentials, which allows remote attackers to estab…

Mitigation only
Fix from $1,950 2008-03-10
Wrt54g HIGH 7.8
CVE-2008-1265

The Linksys WRT54G router allows remote attackers to cause a denial of service (device restart) via a long username and password to the FTP interface.

Mitigation only
Fix from $1,950 2008-03-10
Wrt54g HIGH 7.5
CVE-2008-1264

The Linksys WRT54G router has "admin" as its default FTP password, which allows remote attackers to access sensitive files including nvram.cfg, a fil…

Mitigation only
Fix from $1,950 2008-03-10
Wrt54gl HIGH 9.3
CVE-2008-0228

Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote at…

Mitigation only
Fix from $1,950 2008-01-10
Spa941 HIGH 7.8
CVE-2007-2270EPSS 9%

The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, an…

No fix yet
Fix from $1,950 2007-04-25
Wag200g MEDIUM 5.0
CVE-2007-1585

The Linksys WAG200G with firmware 1.01.01, WRT54GC 2 with firmware 1.00.7, and WRT54GC 1 with firmware 1.03.0 and earlier allow remote attackers to o…

Fix: after 1.03.0
Fix from $1,600 2007-03-21
Spa921 HIGH 7.8
CVE-2006-7121

The HTTP server in Linksys SPA-921 VoIP Desktop Phone allows remote attackers to cause a denial of service (reboot) via (1) a long URL, or a long (2)…

Mitigation only
Fix from $1,950 2007-03-06
Wip 330 Wireless G Ip Phone HIGH 7.8
CVE-2006-6411

PhoneCtrl.exe in Linksys WIP 330 Wireless-G IP Phone 1.00.06A allows remote attackers to cause a denial of service (crash) via a TCP SYN scan, as dem…

Mitigation only
Fix from $1,950 2006-12-10
Wpc300n Wireless N Notebook Adapter Driver HIGH 8.3
CVE-2006-5882EPSS 13%

Stack-based buffer overflow in the Broadcom BCMWL5.SYS wireless device driver 3.50.21.10, as used in Cisco Linksys WPC300N Wireless-N Notebook Adapte…

Patch available
Fix from $1,950 2006-11-14
Wrt54g MEDIUM 5.0
CVE-2006-5202

Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary conf…

No fix yet
Fix from $1,600 2006-10-10
Wrt54g HIGH 7.5
CVE-2006-2559

Linksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP reque…

Patch available
Fix from $1,950 2006-05-24
Rt31p2 MEDIUM 5.0
CVE-2006-1973

Multiple unspecified vulnerabilities in Linksys RT31P2 VoIP router allow remote attackers to cause a denial of service via malformed Session Initiati…

Mitigation only
Fix from $1,600 2006-04-21
Wrt54g V5 MEDIUM 5.0
CVE-2006-1067

Linksys WRT54G routers version 5 (running VXWorks) allow remote attackers to cause a denial of service by sending a malformed DCC SEND string to an I…

Mitigation only
Fix from $1,600 2006-03-07
Befw11s4 HIGH 7.8
CVE-2005-4257

Linksys WRT54GS and BEFW11S4 allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destinatio…

No fix yet
Fix from $1,950 2005-12-15
Wrt54g HIGH 7.5
CVE-2005-2799EPSS 71%

Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote attackers to execute arbitra…

Patch available
Fix from $1,950 2005-09-15
Wrt54g HIGH 7.5
CVE-2005-2914

ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, does not use an authenticat…

Mitigation only
Fix from $1,950 2005-09-14