CVE-2024-42633: Command Injection
A Command Injection vulnerability exists in the doupgradepost function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute OS commands with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42633?
CVE-2024-42633 is classified as a high severity vulnerability due to the potential for authenticated attackers to execute OS commands with root privileges.
How do I fix CVE-2024-42633?
To fix CVE-2024-42633, update the Linksys E1500 firmware to a version that addresses this command injection vulnerability.
Who is affected by CVE-2024-42633?
CVE-2024-42633 affects users of the Linksys E1500 router running firmware version 1.0.06.001.
What type of vulnerability is CVE-2024-42633?
CVE-2024-42633 is a command injection vulnerability found in the httpd binary of the Linksys E1500 router.
What could an attacker do with CVE-2024-42633?
An attacker leveraging CVE-2024-42633 can execute arbitrary OS commands on the Linksys E1500 router, potentially compromising the device and connected networks.