First published: Sat Dec 26 2020(Updated: )
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segmentation fault) via a long /goform/langSwitch langSelectionOnly parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linksys Re6500 Firmware | <1.0.012.001 | |
LINKSYS RE6500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35716 is a vulnerability found in Belkin LINKSYS RE6500 devices before version 1.0.012.001.
The severity of CVE-2020-35716 is high, with a severity score of 7.5.
CVE-2020-35716 allows remote attackers to cause a persistent denial of service (segmentation fault) on the affected devices.
To fix CVE-2020-35716, users should update their Belkin LINKSYS RE6500 devices to version 1.0.012.001 or later.
More information about CVE-2020-35716 can be found in the provided references: [Reference 1](https://bugcrowd.com/disclosures/72d7246b-f77f-4f7f-9bd1-fdc35663cc92/linksys-re6500-unauthenticated-rce-working-across-multiple-fw-versions), [Reference 2](https://downloads.linksys.com/support/assets/releasenotes/ExternalReleaseNotes_RE6500_1.0.012.001.txt), [Reference 3](https://resolverblog.blogspot.com/2020/07/linksys-re6500-unauthenticated-rce-full.html)