CVE-2010-2261: Code Injection
Published Jun 10, 2010
·Updated
Linksys WAP54Gv3 firmware 3.04.03 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) data2 and (2) data3 parameters to (a) Debugcommandpage.asp and (b) debug.cgi.
Affected Software
2 affected components
LinkSys WAP54Gv3=3.05.03
LinkSys WAP54Gv3<=3.04.03
Event History
Jun 10, 2010
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-2261?
CVE-2010-2261 has a medium severity rating due to the potential for remote command execution.
2
How do I fix CVE-2010-2261?
To fix CVE-2010-2261, upgrade the Linksys WAP54Gv3 firmware to version 3.05.03 or later.
3
What systems are affected by CVE-2010-2261?
CVE-2010-2261 affects Linksys WAP54Gv3 firmware versions up to and including 3.04.03.
4
Can CVE-2010-2261 be exploited remotely?
Yes, CVE-2010-2261 can be exploited remotely by attackers using specially crafted parameters.
5
What are the potential impacts of CVE-2010-2261?
The potential impacts of CVE-2010-2261 include unauthorized command execution on the affected device.