CVE-2024-33789: Command Injection
Published May 3, 2024
·Updated
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.
Affected Software
3 affected components
LinkSys E5600
All of the following
LinkSys E5600 Firmware=1.1.0.26
LinkSys E5600
Event History
May 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33789?
CVE-2024-33789 has been classified as a high-severity vulnerability due to its command injection capability.
2
How do I fix CVE-2024-33789?
To fix CVE-2024-33789, update the Linksys E5600 to the latest firmware version provided by Linksys.
3
What are the potential impacts of CVE-2024-33789?
CVE-2024-33789 could allow an attacker to execute arbitrary commands on the device, potentially compromising its integrity.
4
Is CVE-2024-33789 exploitable remotely?
Yes, CVE-2024-33789 can be exploited remotely if the API endpoint is accessible from the internet.
5
What affected devices are known for CVE-2024-33789?
The primary affected device for CVE-2024-33789 is the Linksys E5600 with firmware version 1.1.0.26.