CVE-2021-25310: OS Command Injection
UNSUPPORTED WHEN ASSIGNED The administration web interface on Belkin Linksys WRT160NL 1.0.04.002US20130619 devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the uilanguage POST parameter to the apply.cgi form endpoint. This occurs in doupgradepost in minihttpd. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-25310.
What is the severity of CVE-2021-25310?
The severity of CVE-2021-25310 is critical with a CVSS score of 8.8.
How can an attacker exploit CVE-2021-25310?
An attacker can exploit CVE-2021-25310 by sending shell metacharacters in the ui_language POST parameter to the apply.cgi form endpoint of the administration web interface.
Which devices are affected by CVE-2021-25310?
Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices are affected by CVE-2021-25310.
How can I fix CVE-2021-25310?
There is currently no official fix or patch available for CVE-2021-25310. It is recommended to apply security best practices, such as using strong passwords and keeping the device firmware up to date.