First published: Wed May 18 2022(Updated: )
In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device, exhibits multiple remote command injection vulnerabilities. The following parameters in the [form name] form; [list vulnerable parameters], are not properly sanitized after being submitted to the web interface in a POST request. With specially crafted parameters, it is possible to inject a an OS command which will be executed with root privileges, as the web interface, and all processes on the device, run as root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Belkin N300 Firmware | =1.00.08 | |
Belkin N300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Belkin N300 firmware vulnerability is CVE-2022-30105.
The severity of CVE-2022-30105 is critical with a CVSS score of 9.8.
The affected software is Belkin N300 Firmware 1.00.08.
The vulnerability can be exploited through multiple remote command injection vulnerabilities in the script located at /setting_hidden.asp.
There is currently no information on a fix for this vulnerability. It is recommended to follow the provided reference for updates and patches.