First published: Wed Apr 27 2022(Updated: )
Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linksys Mr9600 Firmware | <2.0.5 | |
Linksys MR9600 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24372 is a vulnerability that allows attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share in Linksys MR9600 devices before version 2.0.5.
An attacker can exploit CVE-2022-24372 by creating a symbolic link to the root directory of a NAS SMB share and reading arbitrary files.
CVE-2022-24372 has a severity rating of medium (4.6).
Linksys MR9600 devices before version 2.0.5 are affected by CVE-2022-24372.
To fix CVE-2022-24372, update your Linksys MR9600 firmware to version 2.0.5 or later.