Skip to main content

Vendor archive

linksys CVEs

Beta · best-effort

223 CVEs tagged to vendor linksys27 Critical, 108 High, 73 Medium, 15 Low, 0 Unrated.

CVE-2009-5157

Published Jun 11, 2019

On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c4_ping_ipaddr variable.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-17208

Published Sep 19, 2018

Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts tha…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17411

Published Dec 21, 2017

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. Th…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2014-8244

Published Nov 1, 2014

Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 bui…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2014-8243

Published Nov 1, 2014

Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 bui…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2013-3066

Published Sep 29, 2014

Linksys EA6500 with firmware 1.1.28.147876 does not properly restrict access, which allows remote attackers to obtain sensitive information (clients and router configuration) via…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3065

Published Sep 29, 2014

Cross-site scripting (XSS) vulnerability in the Parental Controls section in Linksys EA6500 with firmware 1.1.28.147876 allows remote authenticated users to inject arbitrary web s…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-3064

Published Sep 29, 2014

Open redirect vulnerability in ui/dynamic/unsecured.html in Linksys EA6500 with firmware 1.1.28.147876 allows remote attackers to redirect users to arbitrary web sites and conduct…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2261

Published Jun 10, 2010

Linksys WAP54Gv3 firmware 3.04.03 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) data2 and (2) data3 parameters to (a) Debug…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-1573

Published Jun 10, 2010

Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attacke…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3341

Published Sep 24, 2009

Buffer overflow on the Linksys WRT54GL wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4594

Published Oct 17, 2008

Unspecified vulnerability in the SNMPv3 component in Linksys WAP4400N firmware 1.2.14 on the Marvell Semiconductor 88W8361P-BEM1 chipset has unknown impact and attack vectors, pro…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4441

Published Oct 14, 2008

The Marvell driver for the Linksys WAP4400N Wi-Fi access point with firmware 1.2.14 on the Marvell 88W8361P-BEM1 chipset, when WEP mode is enabled, does not properly parse malform…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2092

Published May 6, 2008

Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: the severity of this issue has be…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6707

Published Mar 13, 2008

Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware allow remote attackers to inject arbitra…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 223 CVEsPage 7 of 9