CVE-2019-11535: Command Injection
Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execution. An attacker can access system OS configurations and commands that are not intended for use beyond the web UI.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11535?
CVE-2019-11535 is a vulnerability in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) that allows for remote command execution.
How severe is CVE-2019-11535?
CVE-2019-11535 has a severity rating of 9.8 out of 10, which is categorized as critical.
Which Linksys WiFi extender products are affected by CVE-2019-11535?
Linksys WiFi extender products RE6400 and RE6300 through firmware version 1.2.04.022 are affected by CVE-2019-11535.
How can an attacker exploit CVE-2019-11535?
An attacker can exploit CVE-2019-11535 by accessing system OS configurations and running commands through the web interface of the affected Linksys WiFi extenders.
Is there a fix available for CVE-2019-11535?
Yes, a fix is available. It is recommended to update the firmware of the affected Linksys WiFi extenders to a version higher than 1.2.04.022.