CVE-2019-16340: Critical severity linksys velop firmware vulnerability
Published Nov 21, 2019
·Updated
Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfojson.cgi URI.
Affected Software
6 affected components
LinkSys Velop Whw0303 Firmware=1.1.8.192419
LinkSys Velop Whw0303
LinkSys Velop Whw0302 Firmware=1.1.8.192419
LinkSys Velop Whw0302
LinkSys Velop Whw0301 Firmware=1.1.8.192419
LinkSys Velop Whw0301
Remediation
Patch Available
Event History
Nov 21, 2019
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16340?
CVE-2019-16340 is a vulnerability in Belkin Linksys Velop 1.1.8.192419 devices that allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.
2
How severe is CVE-2019-16340?
CVE-2019-16340 has a severity rating of 9.8 (critical).
3
Which software versions are affected by CVE-2019-16340?
CVE-2019-16340 affects Linksys Velop Whw0303 Firmware version 1.1.8.192419.
4
How can I fix CVE-2019-16340?
To fix CVE-2019-16340, update your Belkin Linksys Velop device to the latest firmware version.
5
Where can I find more information about CVE-2019-16340?
You can find more information about CVE-2019-16340 in the release notes provided by Linksys and the referenced URLs in the description.