CVE-2022-38841: Command Injection
Published Apr 16, 2023
·Updated
Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.
Affected Software
4 affected components
All of the following
LinkSys E8450 Firmware=1.1.00
LinkSys E8450
LinkSys E8450 Firmware=1.1.00
LinkSys E8450
Event History
Apr 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-38841.
2
What is the severity of CVE-2022-38841?
The severity of CVE-2022-38841 is high (CVSS score: 8.8).
3
How does the Linksys AX3200 1.1.00 vulnerability occur?
The Linksys AX3200 1.1.00 vulnerability occurs due to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.
4
Which software version is affected by CVE-2022-38841?
The Linksys E8450 Firmware version 1.1.00 is affected by CVE-2022-38841.
5
How can I fix CVE-2022-38841?
To fix CVE-2022-38841, it is recommended to update the Linksys E8450 Firmware to a version that addresses the vulnerability.