CVE-2023-31741: Command Injection
There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters wlssid, wlant, wlrate, WLattenctl, ttcpnum, ttcpsize in the httpd s StartEPI() function, thereby gaining shell privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linksys E2000 router firmwareto a version that resolves this vulnerability.Fixed in 1.0.06
Event History
Frequently Asked Questions
What is CVE-2023-31741?
CVE-2023-31741 is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06.
How does CVE-2023-31741 affect the Linksys E2000 router?
If an attacker gains web management privileges, they can inject commands into specific post request parameters of the router's httpd Start_EPI() function.
What is the severity of CVE-2023-31741?
CVE-2023-31741 has a severity rating of 7.2, which is considered high.
How can an attacker exploit CVE-2023-31741?
An attacker can exploit CVE-2023-31741 by gaining web management privileges and injecting malicious commands into the affected router's post request parameters.
Is there a fix for CVE-2023-31741?
As of now, there is no official fix available for CVE-2023-31741. It is recommended to update the router's firmware if possible and restrict access to the web management interface.