CVE-2024-40495: Code Injection
Published Jul 24, 2024
·Updated
A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute arbitrary code via the hndparentalctrlunblock function.
Affected Software
3 affected components
LinkSys Router E2500
All of the following
LinkSys E2500 Firmware=2.0.00
LinkSys E2500
Event History
Jul 24, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40495?
CVE-2024-40495 is considered a high-severity vulnerability that can lead to arbitrary code execution.
2
How do I fix CVE-2024-40495?
To mitigate CVE-2024-40495, update the firmware of the Linksys Router E2500 to a version that addresses this vulnerability.
3
Who is affected by CVE-2024-40495?
Users of the Linksys Router E2500 with firmware version 2.0.00 are directly affected by CVE-2024-40495.
4
What types of attacks can CVE-2024-40495 facilitate?
CVE-2024-40495 allows authenticated attackers to execute arbitrary code on the affected router.
5
Is CVE-2024-40495 being actively exploited?
As of now, there are reports indicating that CVE-2024-40495 is being actively exploited in the wild.