CVE-2020-35713: OS Command Injection
Published Dec 26, 2020
·Updated
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.
Affected Software
2 affected components
LinkSys Re6500 Firmware<1.0.012.001
LinkSys RE6500
Event History
Dec 26, 2020
CVE Published
via MITRE·12:47 AM
Data Sourced
via MITRE·12:47 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-35713.
2
What is the severity of CVE-2020-35713?
The severity of CVE-2020-35713 is critical.
3
How does CVE-2020-35713 affect Belkin LINKSYS RE6500 devices?
CVE-2020-35713 allows remote attackers to execute arbitrary commands or set a new password on Belkin LINKSYS RE6500 devices.
4
What is the affected software version of Belkin LINKSYS RE6500 devices?
The affected software version of Belkin LINKSYS RE6500 devices is 1.0.012.001.
5
How can I fix CVE-2020-35713?
To fix CVE-2020-35713, update your Belkin LINKSYS RE6500 device firmware to version 1.0.012.001 or above.