CVE-2022-24372: Medium severity linksys mr9600 firmware vulnerability
Published Apr 27, 2022
·Updated
Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share.
Affected Software
2 affected components
LinkSys Mr9600 Firmware<2.0.5
LinkSys MR9600
Event History
Apr 27, 2022
CVE Published
via MITRE·05:23 PM
Data Sourced
via MITRE·05:23 PM
Description
Frequently Asked Questions
1
What is CVE-2022-24372?
CVE-2022-24372 is a vulnerability that allows attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share in Linksys MR9600 devices before version 2.0.5.
2
How can an attacker exploit CVE-2022-24372?
An attacker can exploit CVE-2022-24372 by creating a symbolic link to the root directory of a NAS SMB share and reading arbitrary files.
3
What is the severity of CVE-2022-24372?
CVE-2022-24372 has a severity rating of medium (4.6).
4
What software versions are affected by CVE-2022-24372?
Linksys MR9600 devices before version 2.0.5 are affected by CVE-2022-24372.
5
How can I fix CVE-2022-24372?
To fix CVE-2022-24372, update your Linksys MR9600 firmware to version 2.0.5 or later.